GNOME Display Manager G_Strsplit Function Local Denial Of Service Vulnerability
BID:25191
Info
GNOME Display Manager G_Strsplit Function Local Denial Of Service Vulnerability
| Bugtraq ID: | 25191 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2007-3381 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 03 2007 12:00AM |
| Updated: | Sep 20 2007 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
rPath rPath Linux 1 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 GNOME GDM 2.19.4 GNOME GDM 2.19.3 GNOME GDM 2.19.2 GNOME GDM 2.19.1 GNOME GDM 2.18.3 GNOME GDM 2.18.2 GNOME GDM 2.18.1 GNOME GDM 2.16.6 GNOME GDM 2.16.5 GNOME GDM 2.16.4 GNOME GDM 2.16.3 GNOME GDM 2.16.2 GNOME GDM 2.16.1 GNOME GDM 2.14.12 GNOME GDM 2.14.11 GNOME GDM 2.14.1 Gentoo Linux Foresight Linux Foresight Linux 1.1 |
| Not Vulnerable: |
GNOME GDM 2.19.5 GNOME GDM 2.18.4 GNOME GDM 2.16.7 GNOME GDM 2.14.13 |
Discussion
GNOME Display Manager G_Strsplit Function Local Denial Of Service Vulnerability
GNOME Display Manager is prone to a local denial-of-service vulnerability because the application fails to handle specially crafted GDM socket commands.
A local attacker can exploit this issue to crash the affected application, denying service to legitimate users.
Versions prior to GNOME Display Manager 2.14.13, 2.16.7, 2.18.4, and 2.19.5 are vulnerable.
GNOME Display Manager is prone to a local denial-of-service vulnerability because the application fails to handle specially crafted GDM socket commands.
A local attacker can exploit this issue to crash the affected application, denying service to legitimate users.
Versions prior to GNOME Display Manager 2.14.13, 2.16.7, 2.18.4, and 2.19.5 are vulnerable.
Exploit / POC
GNOME Display Manager G_Strsplit Function Local Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
GNOME Display Manager G_Strsplit Function Local Denial Of Service Vulnerability
Solution:
The vendor has released versions 2.14.13, 2.16.7, 2.18.4, and 2.19.5 to address this issue. Please see the references for more information.
GNOME GDM 2.14.11
GNOME GDM 2.14.12
GNOME GDM 2.16.1
GNOME GDM 2.16.2
GNOME GDM 2.16.3
GNOME GDM 2.16.4
GNOME GDM 2.16.5
GNOME GDM 2.16.6
GNOME GDM 2.18.1
GNOME GDM 2.18.2
GNOME GDM 2.18.3
GNOME GDM 2.19.1
GNOME GDM 2.19.2
GNOME GDM 2.19.3
GNOME GDM 2.19.4
Solution:
The vendor has released versions 2.14.13, 2.16.7, 2.18.4, and 2.19.5 to address this issue. Please see the references for more information.
GNOME GDM 2.14.11
-
GNOME gdm-2.14.13.tar.gz
http://ftp.acc.umu.se/pub/GNOME/sources/gdm/2.14/gdm-2.14.13.tar.gz
GNOME GDM 2.14.12
-
GNOME gdm-2.14.13.tar.gz
http://ftp.acc.umu.se/pub/GNOME/sources/gdm/2.14/gdm-2.14.13.tar.gz
GNOME GDM 2.16.1
-
GNOME gdm-2.16.7.tar.gz
http://ftp.acc.umu.se/pub/GNOME/sources/gdm/2.16/gdm-2.16.7.tar.gz
GNOME GDM 2.16.2
-
GNOME gdm-2.16.7.tar.gz
http://ftp.acc.umu.se/pub/GNOME/sources/gdm/2.16/gdm-2.16.7.tar.gz
GNOME GDM 2.16.3
-
GNOME gdm-2.16.7.tar.gz
http://ftp.acc.umu.se/pub/GNOME/sources/gdm/2.16/gdm-2.16.7.tar.gz
GNOME GDM 2.16.4
-
GNOME gdm-2.16.7.tar.gz
http://ftp.acc.umu.se/pub/GNOME/sources/gdm/2.16/gdm-2.16.7.tar.gz
GNOME GDM 2.16.5
-
GNOME gdm-2.16.7.tar.gz
http://ftp.acc.umu.se/pub/GNOME/sources/gdm/2.16/gdm-2.16.7.tar.gz
GNOME GDM 2.16.6
-
GNOME gdm-2.16.7.tar.gz
http://ftp.acc.umu.se/pub/GNOME/sources/gdm/2.16/gdm-2.16.7.tar.gz
GNOME GDM 2.18.1
-
GNOME gdm-2.18.4.tar.gz
http://ftp.acc.umu.se/pub/GNOME/sources/gdm/2.18/gdm-2.18.4.tar.gz
GNOME GDM 2.18.2
-
GNOME gdm-2.18.4.tar.gz
http://ftp.acc.umu.se/pub/GNOME/sources/gdm/2.18/gdm-2.18.4.tar.gz
GNOME GDM 2.18.3
-
GNOME gdm-2.18.4.tar.gz
http://ftp.acc.umu.se/pub/GNOME/sources/gdm/2.18/gdm-2.18.4.tar.gz
GNOME GDM 2.19.1
-
GNOME gdm-2.19.5.tar.gz
http://ftp.acc.umu.se/pub/GNOME/sources/gdm/2.19/gdm-2.19.5.tar.gz
GNOME GDM 2.19.2
-
GNOME gdm-2.19.5.tar.gz
http://ftp.acc.umu.se/pub/GNOME/sources/gdm/2.19/gdm-2.19.5.tar.gz
GNOME GDM 2.19.3
-
GNOME gdm-2.19.5.tar.gz
http://ftp.acc.umu.se/pub/GNOME/sources/gdm/2.19/gdm-2.19.5.tar.gz
GNOME GDM 2.19.4
-
GNOME gdm-2.19.5.tar.gz
http://ftp.acc.umu.se/pub/GNOME/sources/gdm/2.19/gdm-2.19.5.tar.gz
References
GNOME Display Manager G_Strsplit Function Local Denial Of Service Vulnerability
References:
References:
- GNOME Display Manager 2.14.13 Release Notes (GNOME)
- GNOME Display Manager 2.18.4 Release Notes (GNOME)
- GNOME Display Manager 2.19.5 Release Notes (GNOME)
- GNOME Display Manager Homepage (GNOME)
- GNOME Display Manager 2.16.7 Release Notes (GNOME)
- RHSA-2007:0777-2 gdm security and bug fix update (Red Hat)