CVE-2007-3381

Published Aug 7, 2007

Last updated 6 years ago

Overview

Description
The GDM daemon in GNOME Display Manager (GDM) before 2.14.13, 2.16.x before 2.16.7, 2.18.x before 2.18.4, and 2.19.x before 2.19.5 does not properly handle NULL return values from the g_strsplit function, which allows local users to cause a denial of service (persistent daemon crash) via a crafted command to the daemon's socket, related to (1) gdm.c and (2) gdmconfig.c in daemon/, and (3) gdmconfig.c and (4) gdmflexiserver.c in gui/.
Source
secalert@redhat.com
NVD status
Modified

Social media

Hype score
Not currently trending

Risk scores

CVSS 2.0

Type
Primary
Base score
1.5
Impact score
2.9
Exploitability score
2.7
Vector string
AV:L/AC:M/Au:S/C:N/I:N/A:P

Weaknesses

nvd@nist.gov
CWE-20

Configurations