Oval Definition:oval:org.opensuse.security:def:202027837
Revision Date:2023-06-22Version:1
Title:CVE-2020-27837
Description:

A flaw was found in GDM in versions prior to 3.38.2.1. A race condition in the handling of session shutdown makes it possible to bypass the lock screen for a user that has autologin enabled, accessing their session without authentication. This is similar to CVE-2017-12164, but requires more difficult conditions to exploit.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2020-27837
SUSE CVE-2020-27837
Platform(s):openSUSE Leap 15.4
openSUSE Tumbleweed
SUSE Enterprise Storage 7
SUSE Linux Enterprise Desktop 15 SP2
SUSE Linux Enterprise Desktop 15 SP3
SUSE Linux Enterprise Desktop 15 SP4
SUSE Linux Enterprise Desktop 15 SP5
SUSE Linux Enterprise High Performance Computing 12 SP5
SUSE Linux Enterprise High Performance Computing 15 SP2
SUSE Linux Enterprise High Performance Computing 15 SP3
SUSE Linux Enterprise High Performance Computing 15 SP4
SUSE Linux Enterprise High Performance Computing 15 SP5
SUSE Linux Enterprise Module for Desktop Applications 15 SP2
SUSE Linux Enterprise Module for Desktop Applications 15 SP3
SUSE Linux Enterprise Module for Desktop Applications 15 SP4
SUSE Linux Enterprise Module for Desktop Applications 15 SP5
SUSE Linux Enterprise Real Time 15 SP2
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 15 SP2
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server for SAP Applications 12 SP3
SUSE Linux Enterprise Server for SAP Applications 12 SP4
SUSE Linux Enterprise Server for SAP Applications 12 SP5
SUSE Linux Enterprise Server for SAP Applications 15 SP2
SUSE Linux Enterprise Server for SAP Applications 15 SP3
SUSE Linux Enterprise Server for SAP Applications 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15 SP5
SUSE Linux Enterprise Storage 7
SUSE Linux Enterprise Storage 7.1
SUSE Manager Proxy 4.1
SUSE Manager Proxy 4.2
SUSE Manager Proxy 4.3
SUSE Manager Retail Branch Server 4.1
SUSE Manager Retail Branch Server 4.2
SUSE Manager Retail Branch Server 4.3
SUSE Manager Server 4.1
SUSE Manager Server 4.2
SUSE Manager Server 4.3
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud 9
SUSE OpenStack Cloud Crowbar 8
SUSE OpenStack Cloud Crowbar 9
Product(s):
Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND Package Information
  • gdm-41.0-1.1 is installed
  • OR gdm-branding-upstream-41.0-1.1 is installed
  • OR gdm-devel-41.0-1.1 is installed
  • OR gdm-lang-41.0-1.1 is installed
  • OR gdm-systemd-41.0-1.1 is installed
  • OR gdmflexiserver-41.0-1.1 is installed
  • OR libgdm1-41.0-1.1 is installed
  • OR typelib-1_0-Gdm-1_0-41.0-1.1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise High Performance Computing 12 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP5 is installed
  • AND gdm is not affected
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP3 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP4 is installed
  • AND
  • gdm is not affected
  • OR gdm-lang is not affected
  • OR gdmflexiserver is not affected
  • OR libgdm1 is not affected
  • OR typelib-1_0-Gdm-1_0 is not affected
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server for SAP Applications 12 SP5 is installed
  • AND gdm is not affected
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP3 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP4 is installed
  • AND
  • gdm is not affected
  • OR gdm-lang is not affected
  • OR gdmflexiserver is not affected
  • OR libgdm1 is not affected
  • OR typelib-1_0-Gdm-1_0 is not affected
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND gdm is not affected
  • Definition Synopsis
  • Release Information
  • SUSE OpenStack Cloud 8 is installed
  • OR SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • gdm is not affected
  • OR gdm-lang is not affected
  • OR gdmflexiserver is not affected
  • OR libgdm1 is not affected
  • OR typelib-1_0-Gdm-1_0 is not affected
  • Definition Synopsis
  • Release Information
  • SUSE OpenStack Cloud 9 is installed
  • OR SUSE OpenStack Cloud Crowbar 9 is installed
  • AND Package Information
  • gdm is not affected
  • OR gdm-lang is not affected
  • OR gdmflexiserver is not affected
  • OR libgdm1 is not affected
  • OR typelib-1_0-Gdm-1_0 is not affected
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Desktop 15 SP2 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP2 is installed
  • OR SUSE Linux Enterprise Module for Desktop Applications 15 SP2 is installed
  • OR SUSE Linux Enterprise Server 15 SP2 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP2 is installed
  • OR SUSE Linux Enterprise Storage 7 is installed
  • OR SUSE Manager Proxy 4.1 is installed
  • OR SUSE Manager Retail Branch Server 4.1 is installed
  • OR SUSE Manager Server 4.1 is installed
  • AND gdm is affected
  • OR Package Information
  • SUSE Linux Enterprise Desktop 15 SP3 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP3 is installed
  • OR SUSE Linux Enterprise Module for Desktop Applications 15 SP3 is installed
  • OR SUSE Linux Enterprise Server 15 SP3 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP3 is installed
  • OR SUSE Linux Enterprise Storage 7.1 is installed
  • OR SUSE Manager Proxy 4.2 is installed
  • OR SUSE Manager Retail Branch Server 4.2 is installed
  • OR SUSE Manager Server 4.2 is installed
  • AND
  • gdm is affected
  • OR gdm-devel is affected
  • OR gdm-lang is affected
  • OR gdm-systemd is affected
  • OR gdmflexiserver is affected
  • OR libgdm1 is affected
  • OR typelib-1_0-Gdm-1_0 is affected
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Desktop 15 SP2 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP2 is installed
  • OR SUSE Linux Enterprise Module for Desktop Applications 15 SP2 is installed
  • OR SUSE Linux Enterprise Real Time 15 SP2 is installed
  • OR SUSE Linux Enterprise Server 15 SP2 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP2 is installed
  • OR SUSE Linux Enterprise Storage 7 is installed
  • OR SUSE Manager Proxy 4.1 is installed
  • OR SUSE Manager Retail Branch Server 4.1 is installed
  • OR SUSE Manager Server 4.1 is installed
  • AND gdm is affected
  • OR Package Information
  • SUSE Linux Enterprise Server for SAP Applications 15 SP2 is installed
  • AND
  • gdm is affected
  • OR gdm-devel is affected
  • OR gdm-lang is affected
  • OR gdm-systemd is affected
  • OR gdmflexiserver is affected
  • OR libgdm1 is affected
  • OR typelib-1_0-Gdm-1_0 is affected
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Desktop 15 SP3 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP3 is installed
  • OR SUSE Linux Enterprise Module for Desktop Applications 15 SP3 is installed
  • OR SUSE Linux Enterprise Server 15 SP3 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP3 is installed
  • OR SUSE Linux Enterprise Storage 7.1 is installed
  • OR SUSE Manager Proxy 4.2 is installed
  • OR SUSE Manager Retail Branch Server 4.2 is installed
  • OR SUSE Manager Server 4.2 is installed
  • AND Package Information
  • gdm is affected
  • OR gdm-devel is affected
  • OR gdm-lang is affected
  • OR gdm-systemd is affected
  • OR gdmflexiserver is affected
  • OR libgdm1 is affected
  • OR typelib-1_0-Gdm-1_0 is affected
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Desktop 15 SP2 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP2 is installed
  • OR SUSE Linux Enterprise Module for Desktop Applications 15 SP2 is installed
  • OR SUSE Linux Enterprise Server 15 SP2 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP2 is installed
  • OR SUSE Linux Enterprise Storage 7 is installed
  • OR SUSE Manager Proxy 4.1 is installed
  • OR SUSE Manager Retail Branch Server 4.1 is installed
  • OR SUSE Manager Server 4.1 is installed
  • AND gdm is affected
  • OR Package Information
  • SUSE Enterprise Storage 7 is installed
  • OR SUSE Linux Enterprise Desktop 15 SP3 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP3 is installed
  • OR SUSE Linux Enterprise Module for Desktop Applications 15 SP3 is installed
  • OR SUSE Linux Enterprise Real Time 15 SP2 is installed
  • OR SUSE Linux Enterprise Server 15 SP3 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP2 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP3 is installed
  • OR SUSE Linux Enterprise Storage 7.1 is installed
  • OR SUSE Manager Proxy 4.2 is installed
  • OR SUSE Manager Retail Branch Server 4.2 is installed
  • OR SUSE Manager Server 4.2 is installed
  • AND
  • gdm is affected
  • OR gdm-devel is affected
  • OR gdm-lang is affected
  • OR gdm-systemd is affected
  • OR gdmflexiserver is affected
  • OR libgdm1 is affected
  • OR typelib-1_0-Gdm-1_0 is affected
  • Definition Synopsis
  • openSUSE Leap 15.4 is installed
  • AND Package Information
  • gdm-41.3-150400.2.7 is installed
  • AND gdm is signed with openSUSE key
  • OR
  • gdm-lang-41.3-150400.2.7 is installed
  • AND gdm-lang is signed with openSUSE key
  • OR
  • gdm-schema-41.3-150400.2.7 is installed
  • AND gdm-schema is signed with openSUSE key
  • OR
  • gdmflexiserver-41.3-150400.2.7 is installed
  • AND gdmflexiserver is signed with openSUSE key
  • OR
  • libgdm1-41.3-150400.2.7 is installed
  • AND libgdm1 is signed with openSUSE key
  • OR
  • typelib-1_0-Gdm-1_0-41.3-150400.2.7 is installed
  • AND typelib-1_0-Gdm-1_0 is signed with openSUSE key
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Desktop 15 SP4 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP4 is installed
  • OR SUSE Linux Enterprise Module for Desktop Applications 15 SP4 is installed
  • OR SUSE Linux Enterprise Server 15 SP4 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP4 is installed
  • OR SUSE Manager Proxy 4.3 is installed
  • OR SUSE Manager Retail Branch Server 4.3 is installed
  • OR SUSE Manager Server 4.3 is installed
  • AND Package Information
  • gdm-41.3-150400.2.7 is installed
  • OR gdm-devel-41.3-150400.2.7 is installed
  • OR gdm-lang-41.3-150400.2.7 is installed
  • OR gdm-schema-41.3-150400.2.7 is installed
  • OR gdm-systemd-41.3-150400.2.7 is installed
  • OR gdmflexiserver-41.3-150400.2.7 is installed
  • OR libgdm1-41.3-150400.2.7 is installed
  • OR typelib-1_0-Gdm-1_0-41.3-150400.2.7 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise High Performance Computing 12 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP5 is installed
  • AND gdm is not affected
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP5 is installed
  • AND
  • gdm is not affected
  • OR gdm-lang is not affected
  • OR gdmflexiserver is not affected
  • OR libgdm1 is not affected
  • OR typelib-1_0-Gdm-1_0 is not affected
  • Definition Synopsis
  • SUSE Linux Enterprise Server for SAP Applications 12 SP4 is installed
  • AND Package Information
  • gdm is not affected
  • OR gdm-lang is not affected
  • OR gdmflexiserver is not affected
  • OR libgdm1 is not affected
  • OR typelib-1_0-Gdm-1_0 is not affected
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Desktop 15 SP5 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP5 is installed
  • OR SUSE Linux Enterprise Module for Desktop Applications 15 SP5 is installed
  • OR SUSE Linux Enterprise Server 15 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP5 is installed
  • AND Package Information
  • gdm-41.3-150400.4.6.1 is installed
  • OR gdm-devel-41.3-150400.4.6.1 is installed
  • OR gdm-lang-41.3-150400.4.6.1 is installed
  • OR gdm-schema-41.3-150400.4.6.1 is installed
  • OR gdm-systemd-41.3-150400.4.6.1 is installed
  • OR gdmflexiserver-41.3-150400.4.6.1 is installed
  • OR libgdm1-41.3-150400.4.6.1 is installed
  • OR typelib-1_0-Gdm-1_0-41.3-150400.4.6.1 is installed
  • BACK