First published: Tue Nov 10 2020(Updated: )
gdm3 versions before 3.36.2 or 3.38.2 would start gnome-initial-setup if gdm3 can't contact the accountservice service via dbus in a timely manner; on Ubuntu (and potentially derivatives) this could be be chained with an additional issue that could allow a local user to create a new privileged account.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gnome Gnome Display Manager | <3.36.2 | |
Gnome Gnome Display Manager | >=3.38.0<3.38.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-16125 is a vulnerability in gdm3 versions before 3.36.2 or 3.38.2 that allows the gnome-initial-setup to start if gdm3 can't contact the accountservice service via dbus in a timely manner.
CVE-2020-16125 has a severity rating of 6.8 (high).
The affected software versions for CVE-2020-16125 are gdm3 versions before 3.36.2 and versions between 3.38.0 and 3.38.2.
This vulnerability can be exploited by a local user to create a new privileged account.
Yes, you can find references for CVE-2020-16125 at the following links: [Link 1](https://bugs.launchpad.net/ubuntu/+source/gdm3/+bug/1900314), [Link 2](https://gitlab.gnome.org/GNOME/gdm/-/issues/642), [Link 3](https://securitylab.github.com/advisories/GHSL-2020-202-gdm3-LPE-unresponsive-accounts-daemon).