First published: Wed Feb 06 2019(Updated: )
A vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could bypass the lock screen by selecting the timed login user and waiting for the timer to expire, at which time they would gain access to the logged-in user's session.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gnome Gnome Display Manager | <3.31.4 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =18.10 | |
Redhat Enterprise Linux | =7.0 | |
ubuntu/gdm3 | <3.28.3-0ubuntu18.04.4 | 3.28.3-0ubuntu18.04.4 |
ubuntu/gdm3 | <3.30.1-1ubuntu5.1 | 3.30.1-1ubuntu5.1 |
ubuntu/gdm3 | <3.31.4+ | 3.31.4+ |
ubuntu/gdm3 | <3.31.4+ | 3.31.4+ |
ubuntu/gdm3 | <3.31.4+ | 3.31.4+ |
ubuntu/gdm3 | <3.31.4+ | 3.31.4+ |
ubuntu/gdm3 | <3.31.4+ | 3.31.4+ |
ubuntu/gdm3 | <3.31.4+ | 3.31.4+ |
ubuntu/gdm3 | <3.31.4+ | 3.31.4+ |
ubuntu/gdm3 | <3.31.4+ | 3.31.4+ |
ubuntu/gdm3 | <3.31.4+ | 3.31.4+ |
ubuntu/gdm3 | <3.31.4+ | 3.31.4+ |
ubuntu/gdm3 | <3.31.4+ | 3.31.4+ |
debian/gdm3 | 3.38.2.1-1 43.0-3 46.2-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3825 is a vulnerability in gdm before version 3.31.4 which allows an attacker to bypass the lock screen by exploiting timed login.
CVE-2019-3825 is rated as medium severity with a CVSS score of 6.4.
The affected software versions include gdm3 3.30.2-3, 3.38.2.1-1, 43.0-3, 45.0.1-1, and some versions of gdm3 for Ubuntu.
To fix CVE-2019-3825, update gdm3 to version 3.31.4 or higher.
You can find more information about CVE-2019-3825 in the references provided: [Link 1](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3825), [Link 2](https://usn.ubuntu.com/3892-1/), [Link 3](https://launchpad.net/bugs/cve/CVE-2019-3825).