Vulnerability Name: | CVE-2014-7271 (CCN-98421) | ||||||||||||||||||||
Assigned: | 2014-10-30 | ||||||||||||||||||||
Published: | 2014-10-30 | ||||||||||||||||||||
Updated: | 2018-03-27 | ||||||||||||||||||||
Summary: | Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication. | ||||||||||||||||||||
CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
| ||||||||||||||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P) 3.4 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||||||
Vulnerability Type: | CWE-306 | ||||||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2014-7271 Source: FEDORA Type: Release Notes, Third Party Advisory FEDORA-2014-12308 Source: FEDORA Type: Issue Tracking, Third Party Advisory FEDORA-2014-12442 Source: MLIST Type: Issue Tracking, Mailing List [oss-security] 20141006 Re: various sddm vulnerabilities Source: BID Type: Third Party Advisory, VDB Entry 70767 Source: CCN Type: BID-70767 SDDM CVE-2014-7271 Local Authentication Bypass Vulnerability Source: CCN Type: Red Hat Bugzilla Bug 1149608 (CVE-2014-7271) CVE-2014-7271 sddm: user "sddm" can login without authentication Source: CONFIRM Type: Issue Tracking https://bugzilla.redhat.com/show_bug.cgi?id=1149608 Source: XF Type: Third Party Advisory, VDB Entry sddm-cve20147271-sec-bypass(98421) Source: XF Type: UNKNOWN sddm-cve20147271-sec-bypass(98421) Source: CCN Type: SDDM GIT Repository Never try to login as the user SDDM #279 Source: CONFIRM Type: Patch https://github.com/sddm/sddm/pull/279/files Source: CONFIRM Type: Release Notes https://github.com/sddm/sddm/wiki/0.10.0-Release-Announcement | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |