The GDM daemon in GNOME Display Manager (GDM) before 2.14.13, 2.16.x before 2.16.7, 2.18.x before 2.18.4, and 2.19.x before 2.19.5 does not properly handle NULL return values from the g_strsplit function, which allows local users to cause a denial of service (persistent daemon crash) via a crafted command to the daemon's socket, related to (1) gdm.c and (2) gdmconfig.c in daemon/, and (3) gdmconfig.c and (4) gdmflexiserver.c in gui/.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
No history.
Information
Published : 2007-08-07 10:17
Updated : 2024-02-04 17:13
NVD link : CVE-2007-3381
Mitre link : CVE-2007-3381
CVE.ORG link : CVE-2007-3381
JSON object : View
Products Affected
gnome
- gdm
CWE
CWE-20
Improper Input Validation