2.1
CVSSv2

CVE-2014-0979

Published: 23/01/2014 Updated: 30/10/2018
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The start_authentication function in lightdm-gtk-greeter.c in LightDM GTK+ Greeter prior to 1.7.1 does not properly handle the return value from the lightdm_greeter_get_authentication_user function, which allows local users to cause a denial of service (NULL pointer dereference) via an empty username.

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse opensuse 12.2

opensuse opensuse 13.1

opensuse opensuse 12.3

lightdm gtk\\+ greeter project lightdm gtk\\+ greeter 1.5.2

lightdm gtk\\+ greeter project lightdm gtk\\+ greeter 1.5.1

lightdm gtk\\+ greeter project lightdm gtk\\+ greeter 1.1.3

lightdm gtk\\+ greeter project lightdm gtk\\+ greeter 1.1.2

lightdm gtk\\+ greeter project lightdm gtk\\+ greeter

lightdm gtk\\+ greeter project lightdm gtk\\+ greeter 1.3.0

lightdm gtk\\+ greeter project lightdm gtk\\+ greeter 1.1.6

lightdm gtk\\+ greeter project lightdm gtk\\+ greeter 1.6.1

lightdm gtk\\+ greeter project lightdm gtk\\+ greeter 1.6.0

lightdm gtk\\+ greeter project lightdm gtk\\+ greeter 1.1.5

lightdm gtk\\+ greeter project lightdm gtk\\+ greeter 1.1.4

lightdm gtk\\+ greeter project lightdm gtk\\+ greeter 1.5.0

lightdm gtk\\+ greeter project lightdm gtk\\+ greeter 1.3.1

lightdm gtk\\+ greeter project lightdm gtk\\+ greeter 1.1.1

Vendor Advisories

Debian Bug report logs - #734472 lightdm-gtk-greeter: crash with NULL username Package: lightdm-gtk-greeter; Maintainer for lightdm-gtk-greeter is Debian Xfce Maintainers <debian-xfce@listsdebianorg>; Source for lightdm-gtk-greeter is src:lightdm-gtk-greeter (PTS, buildd, popcon) Reported by: Yves-Alexis Perez <corsac@d ...