[Bug 956259] New: VUL-0: CVE-2015-8316: lightdm: XDMCP denial of service
http://bugzilla.suse.com/show_bug.cgi?id=956259 Bug ID: 956259 Summary: VUL-0: CVE-2015-8316: lightdm: XDMCP denial of service Classification: openSUSE Product: openSUSE Distribution Version: Leap 42.1 Hardware: Other OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: X11 Applications Assignee: sndirsch@suse.com Reporter: abergmann@suse.com QA Contact: qa-bugs@suse.de Found By: Security Response Team Blocker: --- Via oss security:
it seems that some versions of LightDM (1.14 and 1.16 series) are vulnerable to a denial of service when XDMCP server is enabled. When that's the case, an XDMCP request with no address will crash LightDM.
More information can be found in https://bugs.launchpad.net/lightdm/+bug/1516831 and the bug is fixed with 1.14.4 and 1.16.6 (and development release 1.17.2).
it will attempt to access a negative index into an array
Use CVE-2015-8316. The scope of this CVE is only the LightDM behavior. https://bugs.launchpad.net/lightdm/+bug/1516831/comments/6 says "for some reason the X server was sending Request packets with a addresses field empty. Other Ubuntu releases are not doing this." There may be other ongoing research into mishandling of an empty field, especially because the "attack" is now inadvertently occurring in the wild. If there's a related vulnerability in another independent display manager (or if this is somehow a vulnerability in the X server) a different CVE ID would be needed. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-8316 http://seclists.org/oss-sec/2015/q4/352 https://bugs.launchpad.net/lightdm/+bug/1516831/comments/6 -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.suse.com/show_bug.cgi?id=956259
http://bugzilla.suse.com/show_bug.cgi?id=956259#c2
Egbert Eich
http://bugzilla.suse.com/show_bug.cgi?id=956259
http://bugzilla.suse.com/show_bug.cgi?id=956259#c4
Ondřej Súkup
http://bugzilla.suse.com/show_bug.cgi?id=956259
http://bugzilla.suse.com/show_bug.cgi?id=956259#c5
--- Comment #5 from Ondřej Súkup
in Leap:42.1 is version 1.15.0 and in Factory is SR for 1.17.3, so openSUSE is probadly unaffected , see https://bugs.launchpad.net/lightdm/+bug/1516831/comments/5
ahh, my fault 1.15.0 is devel release, not supported by upstream .. probadly affected :( -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com