The start_authentication function in lightdm-gtk-greeter.c in LightDM GTK+ Greeter before 1.7.1 does not properly handle the return value from the lightdm_greeter_get_authentication_user function, which allows local users to cause a denial of service (NULL pointer dereference) via an empty username.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Opensuse | Opensuse | 12.2 (including) | 12.2 (including) |
Opensuse | Opensuse | 12.3 (including) | 12.3 (including) |
Opensuse | Opensuse | 13.1 (including) | 13.1 (including) |
Lightdm-gtk-greeter | Ubuntu | precise | * |
Lightdm-gtk-greeter | Ubuntu | quantal | * |
Lightdm-gtk-greeter | Ubuntu | raring | * |
Lightdm-gtk-greeter | Ubuntu | saucy | * |
Lightdm-gtk-greeter | Ubuntu | upstream | * |