CVE-2016-1000002: Infoleak
gdm3 3.14.2 and possibly later has an information leak before screen lock
Other sources
Gnome GDM 3.14.2 and possibly later are vulnerable to an information disclosure vulnerability, specifically when a laptop screen is closed to trigger the screen lock, and the lid is then re-opened the previous contents of the screen are visible for approx. 1 second, which is long enough to take a picture or video record it before the lock screen kicks in.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1000002?
CVE-2016-1000002 is classified as a moderate severity vulnerability due to the potential for information disclosure.
How do I fix CVE-2016-1000002?
To fix CVE-2016-1000002, upgrade gdm3 to version 3.38.2.1-1 or later on affected systems.
What systems are affected by CVE-2016-1000002?
CVE-2016-1000002 affects gdm3 version 3.14.2 and possibly later versions on various distributions, including Debian and Red Hat.
What type of attack does CVE-2016-1000002 facilitate?
CVE-2016-1000002 facilitates an information leak when a laptop is locked and the screen is reopened.
Is there a public exploit for CVE-2016-1000002?
As of now, there is no known public exploit specifically targeting CVE-2016-1000002.