CVE-2010-2387
Summary
| CVE | CVE-2010-2387 |
|---|---|
| State | PUBLISHED |
| Assigner | oracle |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-12-21 05:46:13 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | vicious-extensions/ve-misc.c in GNOME Display Manager (gdm) 2.20.x before 2.20.11, when GDM debug is enabled, logs the user password when it contains invalid UTF8 encoded characters, which might allow local users to gain privileges by reading the information from syslog logs. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:L/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gnome | Gnome Display Manager | 2.20.0 | All | All | All |
| Application | Gnome | Gnome Display Manager | 2.20.1 | All | All | All |
| Application | Gnome | Gnome Display Manager | 2.20.10 | All | All | All |
| Application | Gnome | Gnome Display Manager | 2.20.2 | All | All | All |
| Application | Gnome | Gnome Display Manager | 2.20.3 | All | All | All |
| Application | Gnome | Gnome Display Manager | 2.20.4 | All | All | All |
| Application | Gnome | Gnome Display Manager | 2.20.5 | All | All | All |
| Application | Gnome | Gnome Display Manager | 2.20.6 | All | All | All |
| Application | Gnome | Gnome Display Manager | 2.20.7 | All | All | All |
| Application | Gnome | Gnome Display Manager | 2.20.8 | All | All | All |
| Application | Gnome | Gnome Display Manager | 2.20.9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2010-2387 Password disclosure vulnerability in GNOME Display Manager (gdm) (Third Party Vulnerability Resolution Blog) | af854a3a-2127-422b-91ae-364da2661108 | blogs.oracle.com | |
| Bug 571846 – user password may end up in /var/log/messages | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.gnome.org | |
| You have travelled where no person has gone before… | af854a3a-2127-422b-91ae-364da2661108 | www.auscert.org.au | US Government Resource |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| www.osvdb.org/66643 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| ftp.gnome.org/pub/GNOME/sources/gdm/2.20/gdm-2.20.11.changes | af854a3a-2127-422b-91ae-364da2661108 | ftp.gnome.org | |
| GNOME Display Manager Password Disclosure Weakness - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Sun Solaris GNOME Display Manager Password Disclosure Weakness - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.