KDE-Workspace 4.10.5 and earlier does not properly handle the return value of the glibc 2.17 crypt and pw_encrypt functions, which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via (1) an invalid salt or a (2) DES or (3) MD5 encrypted password, when FIPS-140 is enable, to KDM or an (4) invalid password to KCheckPass.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Suse | — | Upgrade kdebase4-wallpapersUpgrade kdebase4-workspace-liboxygenstyle-32bitUpgrade kdebase4-workspace-branding-upstreamUpgrade kdm-branding-upstreamUpgrade kdebase4-workspace-liboxygenstyleUpgrade kdebase4-workspace-plasma-engine-akonadiUpgrade kwinUpgrade kdebase4-workspace-ksysguarddUpgrade kdebase4-workspace-develUpgrade sle-sdk-releaseUpgrade kdebase4-workspaceUpgrade kdmUpgrade kdebase4-workspace-plasma-calendarUpgrade kde4-kgreeter-pluginsUpgrade python-kdebase4 | Dec 12, 2013 | Sep 16, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub