CVE-2010-2387: Low severity gnome display manager vulnerability
Published Dec 21, 2012
·Updated
vicious-extensions/ve-misc.c in GNOME Display Manager (gdm) 2.20.x before 2.20.11, when GDM debug is enabled, logs the user password when it contains invalid UTF8 encoded characters, which might allow local users to gain privileges by reading the information from syslog logs.
Affected Software
11 affected components
Gnome GNOME Display Manager=2.20.8
Gnome GNOME Display Manager=2.20.10
Gnome GNOME Display Manager=2.20.6
Gnome GNOME Display Manager=2.20.0
Gnome GNOME Display Manager=2.20.5
Gnome GNOME Display Manager=2.20.1
Gnome GNOME Display Manager=2.20.3
Gnome GNOME Display Manager=2.20.2
Gnome GNOME Display Manager=2.20.9
Gnome GNOME Display Manager=2.20.7
Gnome GNOME Display Manager=2.20.4
Event History
Dec 21, 2012
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-2387?
CVE-2010-2387 is considered a medium severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2010-2387?
To fix CVE-2010-2387, update to GNOME Display Manager version 2.20.11 or later.
3
What software is affected by CVE-2010-2387?
CVE-2010-2387 affects GNOME Display Manager versions 2.20.0 to 2.20.10.
4
What kind of information is exposed by CVE-2010-2387?
CVE-2010-2387 can log user passwords when they contain invalid UTF8 encoded characters.
5
Is CVE-2010-2387 exploitable remotely?
CVE-2010-2387 is not directly exploitable remotely as it requires local access to the system.