Vulnerability Name: | CVE-2013-2179 (CCN-85130) | ||||||||||||||||||||||||
Assigned: | 2013-06-11 | ||||||||||||||||||||||||
Published: | 2013-06-11 | ||||||||||||||||||||||||
Updated: | 2013-12-27 | ||||||||||||||||||||||||
Summary: | X.Org xdm 1.1.10, 1.1.11, and possibly other versions, when performing authentication using certain implementations of the crypt API function that can return NULL, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by attempting to log into an account whose password field contains invalid characters, as demonstrated using the crypt function from glibc 2.17 and later with (1) the "!" character in the salt portion of a password field or (2) a password that has been encrypted using DES or MD5 in FIPS-140 mode. | ||||||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-310 | ||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||
References: | Source: CCN Type: X.org GIT Repository XDM Source: CONFIRM Type: Exploit, Patch http://cgit.freedesktop.org/xorg/app/xdm/commit/?id=8d1eb5c74413e4c9a21f689fc106949b121c0117 Source: MITRE Type: CNA CVE-2013-2179 Source: SUSE Type: UNKNOWN openSUSE-SU-2013:1117 Source: CCN Type: oss-sec mailing list, Tue, 11 Jun 2013 16:47:40 -0700 CVE request for possible NULL ptr deref in XDM when using crypt() from glibc 2.17+ Source: MLIST Type: UNKNOWN [oss-security] 20130613 Re: CVE request for possible NULL ptr deref in XDM when using crypt() from glibc 2.17+ Source: CCN Type: OSVDB ID: 94236 X.Org xdm crypt() Function NULL Pointer Dereference Remote DoS Source: CCN Type: BID-60486 X.org XDM NULL Pointer Dereference Denial of Service Vulnerability Source: CONFIRM Type: UNKNOWN https://bugs.mageia.org/show_bug.cgi?id=10682 Source: XF Type: UNKNOWN xorg-xdm-cve20132179-dos(85130) Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-2179 | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |