|
|
| |
|
| |
xdm: denial of service
| Package(s): | xdm |
CVE #(s): | CVE-2013-2179
|
| Created: | July 2, 2013 |
Updated: | July 3, 2013 |
| Description: |
From the openSUSE advisory:
xdm was updated on crypt() NULL pointer crashes:
* Starting with glibc 2.17 (eglibc 2.17), crypt() fails
with EINVAL (w/ NULL return) if the salt violates
specifications. Additionally, on FIPS-140 enabled Linux
systems, DES/MD5-encrypted passwords passed to crypt()
fail with EPERM (w/ NULL return). If using glibc's
crypt(), check return value to avoid a possible NULL
pointer dereference. |
| Alerts: |
|
( Log in to post comments)
|
|
|