First published: Fri Dec 11 2020(Updated: )
A flaw was found in GDM in versions prior to 3.38.2.1. A race condition in the handling of session shutdown makes it possible to bypass the lock screen for a user that has autologin enabled, accessing their session without authentication. This is similar to CVE-2017-12164, but requires more difficult conditions to exploit.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/gdm | <3.38.2.1 | 3.38.2.1 |
Gnome Gnome Display Manager | <3.38.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27837 is a vulnerability found in GDM versions prior to 3.38.2.1.
The severity of CVE-2020-27837 is medium with a CVSS score of 6.4.
CVE-2020-27837 can be exploited by bypassing the lock screen for a user with autologin enabled, allowing unauthorized access to their session.
To fix CVE-2020-27837, update GDM to version 3.38.2.1 or later.
Yes, you can find more information about CVE-2020-27837 at the following references: [Reference 1](https://access.redhat.com/security/cve/CVE-2017-12164), [Reference 2](https://gitlab.gnome.org/GNOME/gdm/-/issues/660), [Reference 3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1908276).