PT-2013-4865 · Gnu+2 · Glibc+2

Mancha

·

Publicado

2013-09-01

·

Atualizado

2018-10-30

·

CVE-2013-4132

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions KDE-Workspace versions 4.10.5 and earlier
Description The issue arises from improper handling of the return value of the glibc 2.17 crypt and pw encrypt functions. This allows remote attackers to cause a denial of service, resulting in a NULL pointer dereference and crash. The attack can be initiated via an invalid salt or a DES or MD5 encrypted password when FIPS-140 is enabled, targeting KDM, or through an invalid password to KCheckPass.
Recommendations For KDE-Workspace versions 4.10.5 and earlier, consider updating to a version that properly handles the return value of the glibc crypt and pw encrypt functions to prevent the denial of service. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-4132
MGASA-2013-0269
SUSE-SU-2014_0885-1

Produtos afetados

Kde-Workspace
Suse
Glibc