LWN.net Logo

xdm: denial of service

Package(s):xdm CVE #(s):CVE-2013-2179
Created:July 2, 2013 Updated:July 3, 2013
Description: From the openSUSE advisory:

xdm was updated on crypt() NULL pointer crashes:
* Starting with glibc 2.17 (eglibc 2.17), crypt() fails with EINVAL (w/ NULL return) if the salt violates specifications. Additionally, on FIPS-140 enabled Linux systems, DES/MD5-encrypted passwords passed to crypt() fail with EPERM (w/ NULL return). If using glibc's crypt(), check return value to avoid a possible NULL pointer dereference.

Alerts:
openSUSE openSUSE-SU-2013:1117-1 2013-07-02

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds