Vulnerability Description
The daemon in GDM through 3.29.1 does not properly unexport display objects from its D-Bus interface when they are destroyed, which allows a local attacker to trigger a use-after-free via a specially crafted sequence of D-Bus method calls, resulting in a denial of service or potential code execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnome | Gnome Display Manager | <= 3.29.1 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/105179Third Party AdvisoryVDB Entry
- https://gitlab.gnome.org/GNOME/gdm/issues/401Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/09/msg00003.htmlMailing List
- https://usn.ubuntu.com/3737-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4270Third Party Advisory
- http://www.securityfocus.com/bid/105179Third Party AdvisoryVDB Entry
- https://gitlab.gnome.org/GNOME/gdm/issues/401Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/09/msg00003.htmlMailing List
- https://usn.ubuntu.com/3737-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4270Third Party Advisory
FAQ
What is CVE-2018-14424?
CVE-2018-14424 is a vulnerability with a CVSS score of 7.8 (HIGH). The daemon in GDM through 3.29.1 does not properly unexport display objects from its D-Bus interface when they are destroyed, which allows a local attacker to trigger a use-after-free via a specially ...
How severe is CVE-2018-14424?
CVE-2018-14424 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-14424?
Check the references section above for vendor advisories and patch information. Affected products include: Gnome Gnome Display Manager.