CVE Vulnerabilities

CVE-2014-0979

Published: Jan 23, 2014 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The start_authentication function in lightdm-gtk-greeter.c in LightDM GTK+ Greeter before 1.7.1 does not properly handle the return value from the lightdm_greeter_get_authentication_user function, which allows local users to cause a denial of service (NULL pointer dereference) via an empty username.

Affected Software

NameVendorStart VersionEnd Version
OpensuseOpensuse12.2 (including)12.2 (including)
OpensuseOpensuse12.3 (including)12.3 (including)
OpensuseOpensuse13.1 (including)13.1 (including)
Lightdm-gtk-greeterUbuntuprecise*
Lightdm-gtk-greeterUbuntuquantal*
Lightdm-gtk-greeterUbunturaring*
Lightdm-gtk-greeterUbuntusaucy*
Lightdm-gtk-greeterUbuntuupstream*

References