CVE-2007-3381
CVE-2007-3381
The GDM daemon in GNOME Display Manager (GDM) before 2.14.13, 2.16.x before 2.16.7, 2.18.x before 2.18.4, and 2.19.x before 2.19.5 does not properly handle NULL return values from the g_strsplit function, which allows local users to cause a denial of service (persistent daemon crash) via a crafted command to the daemon's socket, related to (1) gdm.c and (2) gdmconfig.c in daemon/, and (3) gdmconfig.c and (4) gdmflexiserver.c in gui/.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://ftp.gnome.org/pub/GNOME/sources/gdm/2.14/gdm-2.14.13.newshttp://ftp.gnome.org/pub/GNOME/sources/gdm/2.16/gdm-2.16.7.changeshttp://ftp.gnome.org/pub/GNOME/sources/gdm/2.18/gdm-2.18.4.newshttp://ftp.gnome.org/pub/GNOME/sources/gdm/2.19/gdm-2.19.5.newshttp://secunia.com/advisories/26313http://secunia.com/advisories/26368http://secunia.com/advisories/26520http://secunia.com/advisories/26879http://secunia.com/advisories/26900http://security.gentoo.org/glsa/glsa-200709-11.xmlhttps://issues.rpath.com/browse/RPL-1599https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10887