First published: Mon Nov 23 2015(Updated: )
Array index error in LightDM (aka Light Display Manager) 1.14.3, 1.16.x before 1.16.6 when the XDMCP server is enabled allows remote attackers to cause a denial of service (process crash) via an XDMCP request packet with no address.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
LightDM | =1.14.3 | |
LightDM | =1.16 | |
LightDM | =1.16.1 | |
LightDM | =1.16.2 | |
LightDM | =1.16.3 | |
LightDM | =1.16.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8316 has a severity rating that allows remote attackers to cause a denial of service due to an array index error.
To fix CVE-2015-8316, update LightDM to version 1.16.6 or later.
LightDM versions 1.14.3 and all 1.16.x versions prior to 1.16.6 are affected by CVE-2015-8316.
CVE-2015-8316 enables remote attackers to initiate a denial of service attack resulting in a process crash.
Yes, the vulnerability occurs when the XDMCP server is enabled in LightDM.