Vulnerability Name:

CVE-2003-0793 (CCN-13447)

Assigned:2003-10-16
Published:2003-10-16
Updated:2017-07-11
Summary:GDM 2.4.4.x before 2.4.4.4, and 2.4.1.x before 2.4.1.7, does not restrict the size of input, which allows attackers to cause a denial of service (memory consumption).
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2003-0793

Source: CONFIRM
Type: UNKNOWN
http://cvs.gnome.org/bonsai/cvsblame.cgi?file=gdm2/NEWS&rev=&root=/cvs/gnome

Source: CONECTIVA
Type: UNKNOWN
CLA-2003:766

Source: CCN
Type: Conectiva Linux Security Announcement CLSA-2003:766
gdm

Source: MANDRAKE
Type: UNKNOWN
MDKSA-2003:100

Source: CCN
Type: OSVDB ID: 2683
GDM Input Size Memory Consumption Local DoS

Source: BID
Type: Patch, Vendor Advisory
8846

Source: CCN
Type: BID-8846
Multiple GDM Local Denial Of Service Vulnerabilities

Source: CCN
Type: slackware-security Mailing List, Mon, 27 Oct 2003 12:07:30 -0800 (PST)
gdm security update (SSA:2003-300-01)

Source: XF
Type: UNKNOWN
gdm-dos(13447)

Source: XF
Type: UNKNOWN
gdm-dos(13447)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:gnome:gdm:2.2.5.4:*:*:*:*:*:*:*
  • OR cpe:/a:gnome:gdm:2.4.1:*:*:*:*:*:*:*
  • OR cpe:/a:gnome:gdm:2.4.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:gnome:gdm:2.4.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:gnome:gdm:2.4.1.3:*:*:*:*:*:*:*
  • OR cpe:/a:gnome:gdm:2.4.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:gnome:gdm:2.4.1.5:*:*:*:*:*:*:*
  • OR cpe:/a:gnome:gdm:2.4.1.6:*:*:*:*:*:*:*
  • OR cpe:/a:gnome:gdm:2.4.4:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20030793
    V
    CVE-2003-0793
    2015-11-16
    BACK
    gnome gdm 2.2.5.4
    gnome gdm 2.4.1
    gnome gdm 2.4.1.1
    gnome gdm 2.4.1.2
    gnome gdm 2.4.1.3
    gnome gdm 2.4.1.4
    gnome gdm 2.4.1.5
    gnome gdm 2.4.1.6
    gnome gdm 2.4.4