Bug 1049420 (CVE-2014-0979)

Summary: CVE-2014-0979 lightdm-gtk: local DoS due to NULL pointer dereference
Product: [Other] Security Response Reporter: Ratul Gupta <ratulg>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: besser82, christoph.wickert, dan.mashal, gregor, rdieter
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2018-01-05 10:30:44 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1049422    
Bug Blocks:    
Attachments:
Description Flags
Patch for this vulnerability. none

Description Ratul Gupta 2014-01-07 14:53:24 UTC
lightdm-gtk was found to be affected by a vulnerability, which causes it to crash with no username entered and hitting the ENTER.

The issue seems to be a local DoS due to NULL pointer dereference, which can be triggered by any unprivileged attacker requiring the intervention of an administrator to restart lightdm. When a greeter crashes the lightdm daemon exits.

References:
http://seclists.org/oss-sec/2014/q1/30
https://bugzilla.novell.com/show_bug.cgi?id=857303

Comment 1 Ratul Gupta 2014-01-07 14:54:05 UTC
Created lightdm-gtk tracking bugs for this issue:

Affects: fedora-all [bug 1049422]

Comment 2 Ratul Gupta 2014-01-07 15:00:59 UTC
Created attachment 846727 [details]
Patch for this vulnerability.

Though this patch is for lightdm-gtk 1.3, it is reported to work on lightdm-gtk 1.6 as well.

Comment 3 Vincent Danen 2014-01-07 17:31:59 UTC
Upstream report: https://bugs.launchpad.net/lightdm-gtk-greeter/+bug/1266449

Comment 5 Fedora Update System 2014-02-11 23:08:31 UTC
lightdm-gtk-1.6.1-3.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 6 Fedora Update System 2014-02-11 23:14:27 UTC
lightdm-gtk-1.6.1-3.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.