First published: Fri Dec 21 2012(Updated: )
vicious-extensions/ve-misc.c in GNOME Display Manager (gdm) 2.20.x before 2.20.11, when GDM debug is enabled, logs the user password when it contains invalid UTF8 encoded characters, which might allow local users to gain privileges by reading the information from syslog logs.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
GNOME Display Manager | =2.20.8 | |
GNOME Display Manager | =2.20.10 | |
GNOME Display Manager | =2.20.6 | |
GNOME Display Manager | =2.20.0 | |
GNOME Display Manager | =2.20.5 | |
GNOME Display Manager | =2.20.1 | |
GNOME Display Manager | =2.20.3 | |
GNOME Display Manager | =2.20.2 | |
GNOME Display Manager | =2.20.9 | |
GNOME Display Manager | =2.20.7 | |
GNOME Display Manager | =2.20.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2387 is considered a medium severity vulnerability due to its potential for privilege escalation.
To fix CVE-2010-2387, update to GNOME Display Manager version 2.20.11 or later.
CVE-2010-2387 affects GNOME Display Manager versions 2.20.0 to 2.20.10.
CVE-2010-2387 can log user passwords when they contain invalid UTF8 encoded characters.
CVE-2010-2387 is not directly exploitable remotely as it requires local access to the system.