CVE-2014-0979

The start_authentication function in lightdm-gtk-greeter.c in LightDM GTK+ Greeter before 1.7.1 does not properly handle the return value from the lightdm_greeter_get_authentication_user function, which allows local users to cause a denial of service (NULL pointer dereference) via an empty username.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
2.1 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 5%
VendorProductVersion
opensuseopensuse
12.2
opensuseopensuse
12.3
opensuseopensuse
13.1
lightdm_gtk\+_greeter_projectlightdm_gtk\+_greeter
𝑥
≤ 1.7.0
lightdm_gtk\+_greeter_projectlightdm_gtk\+_greeter
1.1.1
lightdm_gtk\+_greeter_projectlightdm_gtk\+_greeter
1.1.2
lightdm_gtk\+_greeter_projectlightdm_gtk\+_greeter
1.1.3
lightdm_gtk\+_greeter_projectlightdm_gtk\+_greeter
1.1.4
lightdm_gtk\+_greeter_projectlightdm_gtk\+_greeter
1.1.5
lightdm_gtk\+_greeter_projectlightdm_gtk\+_greeter
1.1.6
lightdm_gtk\+_greeter_projectlightdm_gtk\+_greeter
1.3.0
lightdm_gtk\+_greeter_projectlightdm_gtk\+_greeter
1.3.1
lightdm_gtk\+_greeter_projectlightdm_gtk\+_greeter
1.5.0
lightdm_gtk\+_greeter_projectlightdm_gtk\+_greeter
1.5.1
lightdm_gtk\+_greeter_projectlightdm_gtk\+_greeter
1.5.2
lightdm_gtk\+_greeter_projectlightdm_gtk\+_greeter
1.6.0
lightdm_gtk\+_greeter_projectlightdm_gtk\+_greeter
1.6.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
lightdm-gtk-greeter
bookworm
2.0.8-2
fixed
bullseye
2.0.8-2
fixed
wheezy
not-affected
sid
2.0.9-1
fixed
trixie
2.0.9-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
lightdm-gtk-greeter
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
dne
saucy
ignored
raring
ignored
quantal
ignored
precise
ignored
lucid
dne