CVE Database
/

CVE-2007-3381

Back to search

CVE-2007-3381

Published: Aug 7, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

The GDM daemon in GNOME Display Manager (GDM) before 2.14.13, 2.16.x before 2.16.7, 2.18.x before 2.18.4, and 2.19.x before 2.19.5 does not properly handle NULL return values from the g_strsplit function, which allows local users to cause a denial of service (persistent daemon crash) via a crafted command to the daemon's socket, related to (1) gdm.c and (2) gdmconfig.c in daemon/, and (3) gdmconfig.c and (4) gdmflexiserver.c in gui/.

VendorProductVersions

n/a

n/a

affected
n/a

References

GLSA-200709-11
vendor-advisory
x_refsource_GENTOO
26313
third-party-advisory
x_refsource_SECUNIA
ADV-2007-2781
vdb-entry
x_refsource_VUPEN
25191
vdb-entry
x_refsource_BID
26879
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:10887
vdb-entry
signature
x_refsource_OVAL
26368
third-party-advisory
x_refsource_SECUNIA
MDKSA-2007:169
vendor-advisory
x_refsource_MANDRIVA
20070803 FLEA-2007-0041-1 gdm
mailing-list
x_refsource_BUGTRAQ
RHSA-2007:0777
vendor-advisory
x_refsource_REDHAT
1018523
vdb-entry
x_refsource_SECTRACK
26900
third-party-advisory
x_refsource_SECUNIA
26520
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now