First published: Mon Jul 30 2012(Updated: )
It was reported [1],[2] that when the fallback greeter is used in GDM3.x, if the disable-user-list setting is "true" (so a user list is not displayed, but entry fields for username and password), if a user enters their username and are then presented with a password prompt, if they were to click the "cancel" button then all of the user-interactive fields disappear. The user is then unable to login in or otherwise interact with the display manager, and must either kill X or reboot. There is no upstream fix as of yet. <a href="https://access.redhat.com/security/cve/CVE-2013-7273">CVE-2013-7273</a> was assigned [3] to this issue. [1] <a href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=683338">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=683338</a> [2] <a href="https://bugzilla.gnome.org/show_bug.cgi?id=704284">https://bugzilla.gnome.org/show_bug.cgi?id=704284</a> [3] <a href="http://seclists.org/oss-sec/2014/q1/40">http://seclists.org/oss-sec/2014/q1/40</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/gdm3 | <=3.4.1-2<=3.4.1-8 | 3.8.3-1 |
Gnome Gnome Display Manager | <=3.4.1 | |
Gnome Gnome Display Manager | =3.0.0 | |
Gnome Gnome Display Manager | =3.0.2 | |
Gnome Gnome Display Manager | =3.0.3 | |
Gnome Gnome Display Manager | =3.0.4 | |
Gnome Gnome Display Manager | =3.1.2 | |
Gnome Gnome Display Manager | =3.1.90 | |
Gnome Gnome Display Manager | =3.1.91 | |
Gnome Gnome Display Manager | =3.1.92 | |
Gnome Gnome Display Manager | =3.2.0 | |
Gnome Gnome Display Manager | =3.2.1 | |
Gnome Gnome Display Manager | =3.2.1.1 | |
Gnome Gnome Display Manager | =3.3.92 | |
Gnome Gnome Display Manager | =3.3.92.1 | |
Gnome Gnome Display Manager | =3.4.0 | |
Gnome Gnome Display Manager | =3.4.0.1 | |
debian/gdm3 | 3.30.2-3 3.38.2.1-1 43.0-3 45.0.1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.