CVE Vulnerabilities

CVE-2010-2387

Published: Dec 21, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
1.9 LOW
AV:L/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
1 N/A
AV:L/AC:H/Au:S/C:P/I:N/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

vicious-extensions/ve-misc.c in GNOME Display Manager (gdm) 2.20.x before 2.20.11, when GDM debug is enabled, logs the user password when it contains invalid UTF8 encoded characters, which might allow local users to gain privileges by reading the information from syslog logs.

Affected Software

NameVendorStart VersionEnd Version
Gnome_display_managerGnome2.20.0 (including)2.20.0 (including)
Gnome_display_managerGnome2.20.1 (including)2.20.1 (including)
Gnome_display_managerGnome2.20.2 (including)2.20.2 (including)
Gnome_display_managerGnome2.20.3 (including)2.20.3 (including)
Gnome_display_managerGnome2.20.4 (including)2.20.4 (including)
Gnome_display_managerGnome2.20.5 (including)2.20.5 (including)
Gnome_display_managerGnome2.20.6 (including)2.20.6 (including)
Gnome_display_managerGnome2.20.7 (including)2.20.7 (including)
Gnome_display_managerGnome2.20.8 (including)2.20.8 (including)
Gnome_display_managerGnome2.20.9 (including)2.20.9 (including)
Gnome_display_managerGnome2.20.10 (including)2.20.10 (including)
GdmUbuntuhardy*
GdmUbuntuupstream*

References