Candidate: CVE-2010-2387 PublicDate: 2012-12-21 05:46:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2387 http://www.auscert.org.au/13123 https://bugzilla.gnome.org/show_bug.cgi?id=571846 https://blogs.oracle.com/sunsecurity/entry/cve_2010_2387_password_disclosure http://xforce.iss.net/xforce/xfdb/60642 http://secunia.com/advisories/40780 http://secunia.com/advisories/40690 http://ftp.gnome.org/pub/GNOME/sources/gdm/2.20/gdm-2.20.11.changes Description: vicious-extensions/ve-misc.c in GNOME Display Manager (gdm) 2.20.x before 2.20.11, when GDM debug is enabled, logs the user password when it contains invalid UTF8 encoded characters, which might allow local users to gain privileges by reading the information from syslog logs. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_gdm: upstream: https://bugzilla.gnome.org/attachment.cgi?id=161016 upstream_gdm: released (2.20.11) hardy_gdm: ignored (reached end-of-life) lucid_gdm: not-affected (2.30.2.is.2.30.0-0ubuntu5.2) oneiric_gdm: not-affected (3.0.4-0ubuntu11) precise_gdm: not-affected (3.0.4-0ubuntu15) quantal_gdm: not-affected (3.6.1-0ubuntu1) devel_gdm: not-affected (3.6.1-0ubuntu1)