CVE-2007-4569: Medium severity KDE kde vulnerability
backend/session.c in KDM in KDE 3.3.0 through 3.5.7, when autologin is configured and "shutdown with password" is enabled, allows remote attackers to bypass the password requirement and login to arbitrary accounts via unspecified vectors.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4569?
CVE-2007-4569 is considered a high severity vulnerability due to the potential for remote attackers to gain unauthorized access.
How do I fix CVE-2007-4569?
To fix CVE-2007-4569, ensure that autologin is not configured and disable the 'shutdown with password' option in KDM settings.
Which versions of KDE are affected by CVE-2007-4569?
CVE-2007-4569 affects KDE versions 3.3.0 to 3.5.7 including various specific updates within that range.
What type of attack does CVE-2007-4569 allow?
CVE-2007-4569 allows remote attackers to bypass password authentication and log in to arbitrary accounts.
Is CVE-2007-4569 still a threat today?
CVE-2007-4569 may still pose a threat to systems that have not been updated and continue to use affected versions of KDE.