Vulnerability Description
The start_authentication function in lightdm-gtk-greeter.c in LightDM GTK+ Greeter before 1.7.1 does not properly handle the return value from the lightdm_greeter_get_authentication_user function, which allows local users to cause a denial of service (NULL pointer dereference) via an empty username.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opensuse | Opensuse | 12.2 |
| Lightdm Gtk\+ Greeter Project | Lightdm Gtk\+ Greeter | <= 1.7.0 |
References
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128117.h
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128150.h
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00048.html
- http://secunia.com/advisories/56211Vendor Advisory
- http://secunia.com/advisories/56423Vendor Advisory
- http://www.openwall.com/lists/oss-security/2014/01/07/15
- http://www.securityfocus.com/bid/64679
- https://bugs.launchpad.net/lightdm-gtk-greeter/+bug/1266449
- https://bugzilla.novell.com/show_bug.cgi?id=857303
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128117.h
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128150.h
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00048.html
- http://secunia.com/advisories/56211Vendor Advisory
- http://secunia.com/advisories/56423Vendor Advisory
- http://www.openwall.com/lists/oss-security/2014/01/07/15
FAQ
What is CVE-2014-0979?
CVE-2014-0979 is a vulnerability with a CVSS score of 2.1 (LOW). The start_authentication function in lightdm-gtk-greeter.c in LightDM GTK+ Greeter before 1.7.1 does not properly handle the return value from the lightdm_greeter_get_authentication_user function, whi...
How severe is CVE-2014-0979?
CVE-2014-0979 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-0979?
Check the references section above for vendor advisories and patch information. Affected products include: Opensuse Opensuse, Lightdm Gtk\+ Greeter Project Lightdm Gtk\+ Greeter.