High severity7.5NVD Advisory· Published Jul 17, 2018· Updated Jun 17, 2026
CVE-2018-14345
CVE-2018-14345
Description
An issue was discovered in SDDM through 0.17.0. If configured with ReuseSession=true, the password is not checked for users with an already existing session. Any user with access to the system D-Bus can therefore unlock any graphical session. This is related to daemon/Display.cpp and helper/backend/PamBackend.cpp.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <=0.17.0
Patches
Vulnerability mechanics
References
2- bugzilla.suse.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
- github.com/sddm/sddm/commit/147cec383892d143b5e02daa70f1e7def50f5d98nvdPatchThird Party Advisory
News mentions
0No linked articles in our index yet.