CVE Vulnerabilities

CVE-2014-0979

Published: Jan 23, 2014 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The start_authentication function in lightdm-gtk-greeter.c in LightDM GTK+ Greeter before 1.7.1 does not properly handle the return value from the lightdm_greeter_get_authentication_user function, which allows local users to cause a denial of service (NULL pointer dereference) via an empty username.

Affected Software

Name Vendor Start Version End Version
Opensuse Opensuse 12.2 (including) 12.2 (including)
Opensuse Opensuse 12.3 (including) 12.3 (including)
Opensuse Opensuse 13.1 (including) 13.1 (including)
Lightdm-gtk-greeter Ubuntu precise *
Lightdm-gtk-greeter Ubuntu quantal *
Lightdm-gtk-greeter Ubuntu raring *
Lightdm-gtk-greeter Ubuntu saucy *
Lightdm-gtk-greeter Ubuntu upstream *

References