PT-2013-4865 · Gnu+2 · Glibc+2
Mancha
·
Published
2013-09-01
·
Updated
2018-10-30
·
CVE-2013-4132
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
KDE-Workspace versions 4.10.5 and earlier
Description
The issue arises from improper handling of the return value of the glibc 2.17 crypt and pw encrypt functions. This allows remote attackers to cause a denial of service, resulting in a NULL pointer dereference and crash. The attack can be initiated via an invalid salt or a DES or MD5 encrypted password when FIPS-140 is enabled, targeting KDM, or through an invalid password to KCheckPass.
Recommendations
For KDE-Workspace versions 4.10.5 and earlier, consider updating to a version that properly handles the return value of the glibc crypt and pw encrypt functions to prevent the denial of service.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kde-Workspace
Suse
Glibc