CVE Vulnerabilities

CVE-2010-2387

Published: Dec 21, 2012 | Modified: Aug 17, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
1.9 LOW
AV:L/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
1 N/A
AV:L/AC:H/Au:S/C:P/I:N/A:N
RedHat/V3
Ubuntu
LOW

vicious-extensions/ve-misc.c in GNOME Display Manager (gdm) 2.20.x before 2.20.11, when GDM debug is enabled, logs the user password when it contains invalid UTF8 encoded characters, which might allow local users to gain privileges by reading the information from syslog logs.

Affected Software

Name Vendor Start Version End Version
Gnome_display_manager Gnome 2.20.0 (including) 2.20.0 (including)
Gnome_display_manager Gnome 2.20.1 (including) 2.20.1 (including)
Gnome_display_manager Gnome 2.20.2 (including) 2.20.2 (including)
Gnome_display_manager Gnome 2.20.3 (including) 2.20.3 (including)
Gnome_display_manager Gnome 2.20.4 (including) 2.20.4 (including)
Gnome_display_manager Gnome 2.20.5 (including) 2.20.5 (including)
Gnome_display_manager Gnome 2.20.6 (including) 2.20.6 (including)
Gnome_display_manager Gnome 2.20.7 (including) 2.20.7 (including)
Gnome_display_manager Gnome 2.20.8 (including) 2.20.8 (including)
Gnome_display_manager Gnome 2.20.9 (including) 2.20.9 (including)
Gnome_display_manager Gnome 2.20.10 (including) 2.20.10 (including)
Gdm Ubuntu hardy *
Gdm Ubuntu upstream *

References