CVE Vulnerabilities

CVE-2019-3825

Improper Authentication

Published: Feb 06, 2019 | Modified: Oct 09, 2019
CVSS 3.x
6.4
MEDIUM
Source:
NVD
CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
6.3 MODERATE
CVSS:3.0/AV:P/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

A vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could bypass the lock screen by selecting the timed login user and waiting for the timer to expire, at which time they would gain access to the logged-in users session.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Gnome_display_manager Gnome * 3.31.4 (excluding)
Red Hat Enterprise Linux 8 RedHat accountsservice-0:0.6.50-8.el8 *
Red Hat Enterprise Linux 8 RedHat appstream-data-0:8-20191129.el8 *
Red Hat Enterprise Linux 8 RedHat baobab-0:3.28.0-4.el8 *
Red Hat Enterprise Linux 8 RedHat clutter-0:1.26.2-8.el8 *
Red Hat Enterprise Linux 8 RedHat evince-0:3.28.4-4.el8 *
Red Hat Enterprise Linux 8 RedHat gdm-1:3.28.3-29.el8 *
Red Hat Enterprise Linux 8 RedHat gjs-0:1.56.2-4.el8 *
Red Hat Enterprise Linux 8 RedHat gnome-boxes-0:3.28.5-8.el8 *
Red Hat Enterprise Linux 8 RedHat gnome-control-center-0:3.28.2-19.el8 *
Red Hat Enterprise Linux 8 RedHat gnome-menus-0:3.13.3-11.el8 *
Red Hat Enterprise Linux 8 RedHat gnome-online-accounts-0:3.28.2-1.el8 *
Red Hat Enterprise Linux 8 RedHat gnome-remote-desktop-0:0.1.6-8.el8 *
Red Hat Enterprise Linux 8 RedHat gnome-session-0:3.28.1-8.el8 *
Red Hat Enterprise Linux 8 RedHat gnome-settings-daemon-0:3.32.0-9.el8 *
Red Hat Enterprise Linux 8 RedHat gnome-shell-0:3.32.2-14.el8 *
Red Hat Enterprise Linux 8 RedHat gnome-software-0:3.30.6-3.el8 *
Red Hat Enterprise Linux 8 RedHat gnome-terminal-0:3.28.3-1.el8 *
Red Hat Enterprise Linux 8 RedHat gnome-tweaks-0:3.28.1-7.el8 *
Red Hat Enterprise Linux 8 RedHat gsettings-desktop-schemas-0:3.32.0-4.el8 *
Red Hat Enterprise Linux 8 RedHat gtk3-0:3.22.30-5.el8 *
Red Hat Enterprise Linux 8 RedHat gvfs-0:1.36.2-8.el8 *
Red Hat Enterprise Linux 8 RedHat LibRaw-0:0.19.5-1.el8 *
Red Hat Enterprise Linux 8 RedHat libvncserver-0:0.9.11-14.el8 *
Red Hat Enterprise Linux 8 RedHat libxslt-0:1.1.32-4.el8 *
Red Hat Enterprise Linux 8 RedHat mozjs52-0:52.9.0-2.el8 *
Red Hat Enterprise Linux 8 RedHat mozjs60-0:60.9.0-4.el8 *
Red Hat Enterprise Linux 8 RedHat mutter-0:3.32.2-34.el8 *
Red Hat Enterprise Linux 8 RedHat nautilus-0:3.28.1-12.el8 *
Red Hat Enterprise Linux 8 RedHat vala-0:0.40.19-1.el8 *
Red Hat Enterprise Linux 8 RedHat vinagre-0:3.22.0-21.el8 *
Red Hat Enterprise Linux 8 RedHat accountsservice-0:0.6.50-8.el8 *
Red Hat Enterprise Linux 8 RedHat appstream-data-0:8-20191129.el8 *
Red Hat Enterprise Linux 8 RedHat baobab-0:3.28.0-4.el8 *
Red Hat Enterprise Linux 8 RedHat clutter-0:1.26.2-8.el8 *
Red Hat Enterprise Linux 8 RedHat evince-0:3.28.4-4.el8 *
Red Hat Enterprise Linux 8 RedHat gdm-1:3.28.3-29.el8 *
Red Hat Enterprise Linux 8 RedHat gjs-0:1.56.2-4.el8 *
Red Hat Enterprise Linux 8 RedHat gnome-boxes-0:3.28.5-8.el8 *
Red Hat Enterprise Linux 8 RedHat gnome-control-center-0:3.28.2-19.el8 *
Red Hat Enterprise Linux 8 RedHat gnome-menus-0:3.13.3-11.el8 *
Red Hat Enterprise Linux 8 RedHat gnome-online-accounts-0:3.28.2-1.el8 *
Red Hat Enterprise Linux 8 RedHat gnome-remote-desktop-0:0.1.6-8.el8 *
Red Hat Enterprise Linux 8 RedHat gnome-session-0:3.28.1-8.el8 *
Red Hat Enterprise Linux 8 RedHat gnome-settings-daemon-0:3.32.0-9.el8 *
Red Hat Enterprise Linux 8 RedHat gnome-shell-0:3.32.2-14.el8 *
Red Hat Enterprise Linux 8 RedHat gnome-software-0:3.30.6-3.el8 *
Red Hat Enterprise Linux 8 RedHat gnome-terminal-0:3.28.3-1.el8 *
Red Hat Enterprise Linux 8 RedHat gnome-tweaks-0:3.28.1-7.el8 *
Red Hat Enterprise Linux 8 RedHat gsettings-desktop-schemas-0:3.32.0-4.el8 *
Red Hat Enterprise Linux 8 RedHat gtk3-0:3.22.30-5.el8 *
Red Hat Enterprise Linux 8 RedHat gvfs-0:1.36.2-8.el8 *
Red Hat Enterprise Linux 8 RedHat LibRaw-0:0.19.5-1.el8 *
Red Hat Enterprise Linux 8 RedHat libvncserver-0:0.9.11-14.el8 *
Red Hat Enterprise Linux 8 RedHat libxslt-0:1.1.32-4.el8 *
Red Hat Enterprise Linux 8 RedHat mozjs52-0:52.9.0-2.el8 *
Red Hat Enterprise Linux 8 RedHat mozjs60-0:60.9.0-4.el8 *
Red Hat Enterprise Linux 8 RedHat mutter-0:3.32.2-34.el8 *
Red Hat Enterprise Linux 8 RedHat nautilus-0:3.28.1-12.el8 *
Red Hat Enterprise Linux 8 RedHat vala-0:0.40.19-1.el8 *
Red Hat Enterprise Linux 8 RedHat vinagre-0:3.22.0-21.el8 *
Gdm3 Ubuntu bionic *
Gdm3 Ubuntu cosmic *
Gdm3 Ubuntu devel *
Gdm3 Ubuntu disco *
Gdm3 Ubuntu eoan *
Gdm3 Ubuntu esm-apps/xenial *
Gdm3 Ubuntu focal *
Gdm3 Ubuntu groovy *
Gdm3 Ubuntu hirsute *
Gdm3 Ubuntu impish *
Gdm3 Ubuntu jammy *
Gdm3 Ubuntu kinetic *
Gdm3 Ubuntu lunar *
Gdm3 Ubuntu mantic *
Gdm3 Ubuntu noble *
Gdm3 Ubuntu oracular *
Gdm3 Ubuntu xenial *

Potential Mitigations

References