CVE-2013-7273: Low severity Gnome GNOME Display Manager vulnerability
GNOME Display Manager (gdm) 3.4.1 and earlier, when disable-user-list is set to true, allows local users to cause a denial of service (unable to login) by pressing the cancel button after entering a user name.
Other sources
It was reported [1],[2] that when the fallback greeter is used in GDM3.x, if the disable-user-list setting is "true" (so a user list is not displayed, but entry fields for username and password), if a user enters their username and are then presented with a password prompt, if they were to click the "cancel" button then all of the user-interactive fields disappear. The user is then unable to login in or otherwise interact with the display manager, and must either kill X or reboot.
There is no upstream fix as of yet. CVE-2013-7273 was assigned [3] to this issue.
[1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=683338 [2] https://bugzilla.gnome.org/showbug.cgi?id=704284 [3] http://seclists.org/oss-sec/2014/q1/40
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/gdm3to a version that resolves this vulnerability.Fixed in 3.8.3-1 - Upgrade
Upgrade
debian/gdm3to a version that resolves this vulnerability.Fixed in 3.38.2.1-1Fixed in 43.0-3Fixed in 48.0-1
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7273?
CVE-2013-7273 is classified as a denial of service vulnerability affecting GNOME Display Manager.
How do I fix CVE-2013-7273?
To fix CVE-2013-7273, upgrade GNOME Display Manager to version 3.8.3-1 or higher.
Which versions of GNOME Display Manager are affected by CVE-2013-7273?
CVE-2013-7273 affects GNOME Display Manager versions 3.4.1 and earlier.
Can CVE-2013-7273 be exploited remotely?
No, CVE-2013-7273 requires local access to exploit the vulnerability.
What is the impact of CVE-2013-7273?
The impact of CVE-2013-7273 is that it can lead to denial of service by preventing local users from logging in.