Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
backend/session.c in KDM in KDE 3.3.0 through 3.5.7, when autologin is configured and "shutdown with password" is enabled, allows remote attackers to bypass the password requirement and login to arbitrary accounts via unspecified vectors.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
KDE KDM绕过口令认证漏洞
Vulnerability Description
KDE是一个为UNIX工作站设计的强大的开源图形桌面环境。KDE中所捆绑的KDM允许用户选择登录的会话类型。 KDM在某种配置情况下存在漏洞,攻击者可能利用此漏洞无需口令非授权访问系统。 当配置了autologin并使能了"shutdown with password"选项,即使帐户有口令保护也可能使攻击者不需要口令登录成功。
CVSS Information
N/A
Vulnerability Type
N/A