CVE-2007-4569
Summary
| CVE | CVE-2007-4569 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-09-21 19:17:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | backend/session.c in KDM in KDE 3.3.0 through 3.5.7, when autologin is configured and "shutdown with password" is enabled, allows remote attackers to bypass the password requirement and login to arbitrary accounts via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Kde | Kde | 3.3 | All | All | All |
| Operating System | Kde | Kde | 3.3.0 | All | All | All |
| Operating System | Kde | Kde | 3.3.1 | All | All | All |
| Operating System | Kde | Kde | 3.3.2 | All | All | All |
| Operating System | Kde | Kde | 3.4 | All | All | All |
| Operating System | Kde | Kde | 3.4.0 | All | All | All |
| Operating System | Kde | Kde | 3.4.1 | All | All | All |
| Operating System | Kde | Kde | 3.4.2 | All | All | All |
| Operating System | Kde | Kde | 3.4.3 | All | All | All |
| Operating System | Kde | Kde | 3.5 | All | All | All |
| Operating System | Kde | Kde | 3.5.0 | All | All | All |
| Operating System | Kde | Kde | 3.5.1 | All | All | All |
| Operating System | Kde | Kde | 3.5.2 | All | All | All |
| Operating System | Kde | Kde | 3.5.3 | All | All | All |
| Operating System | Kde | Kde | 3.5.4 | All | All | All |
| Operating System | Kde | Kde | 3.5.5 | All | All | All |
| Operating System | Kde | Kde | 3.5.6 | All | All | All |
| Operating System | Kde | Kde | 3.5.7 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| KDE KDM Unspecified Password Authentication Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| [SECURITY] Fedora Core 6 Update: kdebase-3.5.7-1.fc6 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| KDE Autologin Authentication Bug May Let Remote Users Login Without a Password - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| SUSE Updates for Multiple Packages - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Ubuntu update for kdm - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Fedora update for kdebase - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| USN-517-1: kdm vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| issues.rpath.com/browse/RPL-1725 | af854a3a-2127-422b-91ae-364da2661108 | issues.rpath.com | |
| Mandriva update for kdebase - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Gentoo update for kdm - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Support / Security / Advisories / / MDKSA-2007:190 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| KDM: Local privilege escalation — Gentoo Linux Documentation | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| [security-announce] SUSE Security Summary Report SUSE-SR:2007:021 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| rPath update for kdebase - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Fedora update for kdebase - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian update for kdebase - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| KDE KDM Login Password Check Security Bypass - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [SECURITY] Fedora 7 Update: kdebase-3.5.7-13.1.fc7 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Red Hat update for kdebase - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian -- Security Information -- DSA-1376-1 kdebase | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| www.kde.org/info/security/advisory-20070919-1.txt | af854a3a-2127-422b-91ae-364da2661108 | www.kde.org | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.