Severity
6.4MEDIUMNVD
CNA4.1
EPSS
0.1%
top 66.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 26
Latest updateMay 13

Description

A flaw was discovered in gdm 3.24.1 where gdm greeter was no longer setting the ran_once boolean during autologin. If autologin was enabled for a victim, an attacker could simply select 'login as another user' to unlock their screen.

CVSS vector

CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 0.5 | Impact: 5.9

Affected Packages2 packages

CVEListV5gnome/gdm3.24.1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-87vr-968r-r3qp: A flaw was discovered in gdm 32022-05-13
OSV
CVE-2017-12164: A flaw was discovered in gdm 32018-07-26
CVEList
CVE-2017-12164: A flaw was discovered in gdm 32018-07-26

📋Vendor Advisories

3
Red Hat
gdm: lock screen bypass when autologin is set2020-12-11
Red Hat
gdm: lock screen can be circumvented when autologin is set2017-06-14
Debian
CVE-2017-12164: gdm3 - A flaw was discovered in gdm 3.24.1 where gdm greeter was no longer setting the ...2017

💬Community

1
Bugzilla
CVE-2017-12164 gdm: lock screen can be circumvented when autologin is set2017-09-11
CVE-2017-12164 — Gnome GDM vulnerability | cvebase