Lucene search

K
freebsdFreeBSD79B616D0-66D1-11DC-B25F-02E0185F8D72
HistorySep 19, 2007 - 12:00 a.m.

kdm -- passwordless login vulnerability

2007-09-1900:00:00
vuxml.freebsd.org
24

CVSS2

6.8

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:S/C:C/I:C/A:C

EPSS

0.004

Percentile

74.3%

The KDE development team reports:

KDM can be tricked into performing a password-less login
even for accounts with a password set under certain
circumstances, namely autologin to be configured and
“shutdown with password” enabled.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchkdebase3< 3.5.7_3UNKNOWN

CVSS2

6.8

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:S/C:C/I:C/A:C

EPSS

0.004

Percentile

74.3%