Lucene search

K
cve[email protected]CVE-2007-3381
HistoryAug 07, 2007 - 10:17 a.m.

CVE-2007-3381

2007-08-0710:17:00
CWE-20
web.nvd.nist.gov
25
cve-2007-3381
gdm
gnome display manager
null return values
denial of service
daemon crash
gdm.c
gdmconfig.c
gdmflexiserver.c

1.5 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:M/Au:S/C:N/I:N/A:P

5.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.1%

The GDM daemon in GNOME Display Manager (GDM) before 2.14.13, 2.16.x before 2.16.7, 2.18.x before 2.18.4, and 2.19.x before 2.19.5 does not properly handle NULL return values from the g_strsplit function, which allows local users to cause a denial of service (persistent daemon crash) via a crafted command to the daemonโ€™s socket, related to (1) gdm.c and (2) gdmconfig.c in daemon/, and (3) gdmconfig.c and (4) gdmflexiserver.c in gui/.

Affected configurations

NVD
Node
gnomegdmRangeโ‰ค2.14.12
OR
gnomegdmMatch0.7
OR
gnomegdmMatch1.0
OR
gnomegdmMatch2.0
OR
gnomegdmMatch2.2
OR
gnomegdmMatch2.3
OR
gnomegdmMatch2.4
OR
gnomegdmMatch2.5
OR
gnomegdmMatch2.6
OR
gnomegdmMatch2.8
OR
gnomegdmMatch2.13
OR
gnomegdmMatch2.14
OR
gnomegdmMatch2.14.1
OR
gnomegdmMatch2.14.2
OR
gnomegdmMatch2.14.3
OR
gnomegdmMatch2.14.4
OR
gnomegdmMatch2.14.5
OR
gnomegdmMatch2.14.6
OR
gnomegdmMatch2.14.7
OR
gnomegdmMatch2.14.8
OR
gnomegdmMatch2.14.9
OR
gnomegdmMatch2.14.10
OR
gnomegdmMatch2.14.11
Node
gnomegdmMatch2.14.3
OR
gnomegdmMatch2.14.4
OR
gnomegdmMatch2.14.5
OR
gnomegdmMatch2.14.6
OR
gnomegdmMatch2.16
OR
gnomegdmMatch2.16.1
OR
gnomegdmMatch2.16.2
Node
gnomegdmMatch2.18
OR
gnomegdmMatch2.18.1
OR
gnomegdmMatch2.18.2
OR
gnomegdmMatch2.18.3
Node
gnomegdmMatch2.19
OR
gnomegdmMatch2.19.1
OR
gnomegdmMatch2.19.2
OR
gnomegdmMatch2.19.3
OR
gnomegdmMatch2.19.4

References

1.5 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:M/Au:S/C:N/I:N/A:P

5.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.1%