First published: Thu Jan 09 2014(Updated: )
It was reported [1],[2] that when the fallback greeter is used in GDM3.x, if the disable-user-list setting is "true" (so a user list is not displayed, but entry fields for username and password), if a user enters their username and are then presented with a password prompt, if they were to click the "cancel" button then all of the user-interactive fields disappear. The user is then unable to login in or otherwise interact with the display manager, and must either kill X or reboot. There is no upstream fix as of yet. <a href="https://access.redhat.com/security/cve/CVE-2013-7273">CVE-2013-7273</a> was assigned [3] to this issue. [1] <a href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=683338">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=683338</a> [2] <a href="https://bugzilla.gnome.org/show_bug.cgi?id=704284">https://bugzilla.gnome.org/show_bug.cgi?id=704284</a> [3] <a href="http://seclists.org/oss-sec/2014/q1/40">http://seclists.org/oss-sec/2014/q1/40</a>
Affected Software | Affected Version | How to fix |
---|---|---|
GNOME libraries | >=3.x |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.