FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

kdm -- passwordless login vulnerability

Affected packages
kdebase3 < 3.5.7_3

Details

VuXML ID 79b616d0-66d1-11dc-b25f-02e0185f8d72
Discovery 2007-09-19
Entry 2007-09-19

The KDE development team reports:

KDM can be tricked into performing a password-less login even for accounts with a password set under certain circumstances, namely autologin to be configured and "shutdown with password" enabled.

References

CVE Name CVE-2007-4569
URL http://www.kde.org/info/security/advisory-20070919-1.txt