PT-2018-12461 · Kde+2 · Sddm+2
Vogtinator
·
Published
2018-07-17
·
Updated
2024-06-15
·
CVE-2018-14345
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SDDM versions prior to 0.17.0
Description
An issue was discovered where the password is not checked for users with an already existing session if SDDM is configured with ReuseSession=true. This allows any user with access to the system D-Bus to unlock any graphical session. The issue is related to the files daemon/Display.cpp and helper/backend/PamBackend.cpp.
Recommendations
For SDDM versions prior to 0.17.0, consider setting ReuseSession=false as a temporary workaround to prevent unauthorized access to graphical sessions. Restrict access to the system D-Bus to minimize the risk of exploitation.
Fix
Insufficient Session Expiration
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Sddm
Suse