CVE-2013-4132: Null Pointer Dereference
KDE-Workspace 4.10.5 and earlier does not properly handle the return value of the glibc 2.17 crypt and pwencrypt functions, which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via (1) an invalid salt or a (2) DES or (3) MD5 encrypted password, when FIPS-140 is enable, to KDM or an (4) invalid password to KCheckPass.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4132?
CVE-2013-4132 is classified as a moderate severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2013-4132?
To mitigate CVE-2013-4132, upgrade KDE Workspace to version 4.10.6 or later.
Which versions are affected by CVE-2013-4132?
CVE-2013-4132 affects KDE-Workspace versions up to and including 4.10.5.
What type of attack does CVE-2013-4132 facilitate?
CVE-2013-4132 allows remote attackers to launch a denial of service attack through NULL pointer dereference.
Does CVE-2013-4132 affect openSUSE?
Yes, CVE-2013-4132 affects openSUSE version 12.2 when using vulnerable KDE components.