Bug 12489 - CVE-2007-3381 in gdm
: CVE-2007-3381 in gdm
Status: CLOSED FIXED
: Sisyphus
(All bugs in Sisyphus/gdm)
: unstable
: all Linux
: P2 normal
Assigned To:
:
: http://ftp.gnome.org/pub/GNOME/source...
:
:
:
  Show dependency tree
 
Reported: 2007-08-06 21:06 by
Modified: 2007-08-15 19:41 (History)


Attachments


Note

You need to log in before you can comment on or make changes to this bug.


Description From 2007-08-06 21:06:52
http://ftp.gnome.org/pub/GNOME/sources/gdm/2.16/gdm-2.16.7.changes

2007-07-30  Brian Cameron  <brian.cameron@sun.com>

	This fixes CVE-2007-3381 - a denial of service attack where
	the user can crash the GDM daemon with a carefully crafted GDM
	sockets command and cause GDM to stop managing future displays.
------- Comment #1 From 2007-08-08 14:27:40 -------
Ловите 2.18.4-alt1.
------- Comment #2 From 2007-08-08 15:41:30 -------
(In reply to comment #1)
> Ловите 2.18.4-alt1.

А в 4.0?
------- Comment #3 From 2007-08-08 16:20:21 -------
Насколько я вижу, специфических для GNOME 2.18 зависимостей у gdm нет, посему
можно сразу переложить. GDM вообще существует слегка отдельно от остального
GNOME, в силу своего положения в системе.