Total vulnerabilities in the database
gdm3 versions before 3.36.2 or 3.38.2 would start gnome-initial-setup if gdm3 can't contact the accountservice service via dbus in a timely manner; on Ubuntu (and potentially derivatives) this could be be chained with an additional issue that could allow a local user to create a new privileged account.
Software | From | Fixed in |
---|---|---|
gnome / gnome_display_manager | - | 3.36.2 |
gnome / gnome_display_manager | 3.38.0 | 3.38.2 |