CVE-2014-0979: Null Pointer Dereference
The startauthentication function in lightdm-gtk-greeter.c in LightDM GTK+ Greeter before 1.7.1 does not properly handle the return value from the lightdmgreetergetauthenticationuser function, which allows local users to cause a denial of service (NULL pointer dereference) via an empty username.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0979?
CVE-2014-0979 has been classified as a medium severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2014-0979?
To fix CVE-2014-0979, update LightDM GTK+ Greeter to version 1.7.1 or later.
What systems are affected by CVE-2014-0979?
CVE-2014-0979 affects LightDM GTK+ Greeter versions up to and including 1.7.0 and specific versions of openSUSE.
What type of vulnerability is CVE-2014-0979?
CVE-2014-0979 is a local denial of service vulnerability caused by improper handling of user input.
Can CVE-2014-0979 be exploited remotely?
No, CVE-2014-0979 can only be exploited by local users with access to the affected system.