MGASA-2014-0026

Source
https://advisories.mageia.org/MGASA-2014-0026.html
Import Source
https://advisories.mageia.org/MGASA-2014-0026.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0026
Upstream
Published
2014-01-24T21:01:31Z
Modified
2026-04-16T06:23:52Z
Summary
Updated lightdm-gtk-greeter fixes CVE-2014-0979
Details

Updated lightdm-gtk-greeter package fixes security vulnerability:

lightdm-gtk-greeter uses the lightdm-gobject API incorrectly and does not handle lightdm_greeter_get_authentication_user() returning NULL when the username of the previous authentication is invalid resulting in a NULL pointer dereference in start_authentication(). This constitutes a local denial of service which can be triggered by any unprivileged attacker requiring the intervention of an administrator to restart lightdm (CVE-2014-0979).

References
Credits

Affected packages

Mageia:3 / lightdm-gtk-greeter

Package

Name
lightdm-gtk-greeter
Purl
pkg:rpm/mageia/lightdm-gtk-greeter?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.3.1-6.1.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2014-0026.json"