Home page logo

oss-sec logo oss-sec mailing list archives

CVE request: lightdm-gtk-greeter - local DOS due to NULL pointer dereference
From: Guido Berhoerster <guido+openwall.com () berhoerster name>
Date: Tue, 7 Jan 2014 11:47:31 +0100


an openSUSE user discovered that it is trivial to crash
lightdm-gtk-greeter by entering an empty username due to a NULL
pointer dereference. When a greeter crashes the lightdm daemon
This constitutes a local denial of service which can be triggered
by any unprivileged attacker requiring the intervention of an
administrator to restart lightdm. It affects all versions of

The initial downstream report is at
https://bugzilla.novell.com/show_bug.cgi?id=857303, the bug has
been reported upstream at
https://bugs.launchpad.net/lightdm-gtk-greeter/+bug/1266449 and
fixes for the 1.1 and 1.3 series are available at

Could a CVE be assigned to this issue please?
Guido Berhoerster

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]