Bug 12489 - CVE-2007-3381 in gdm
Summary: CVE-2007-3381 in gdm
Status: CLOSED FIXED
Alias: None
Product: Sisyphus
Classification: Development
Component: gdm (show other bugs)
Version: unstable
Hardware: all Linux
: P2 normal
Assignee: Alexey Shabalin
QA Contact: qa-sisyphus
URL: http://ftp.gnome.org/pub/GNOME/source...
Keywords:
Depends on:
Blocks:
 
Reported: 2007-08-06 21:06 MSD by Igor Zubkov
Modified: 2007-08-15 19:41 MSD (History)
2 users (show)

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Igor Zubkov 2007-08-06 21:06:52 MSD
http://ftp.gnome.org/pub/GNOME/sources/gdm/2.16/gdm-2.16.7.changes

2007-07-30  Brian Cameron  <brian.cameron@sun.com>

	This fixes CVE-2007-3381 - a denial of service attack where
	the user can crash the GDM daemon with a carefully crafted GDM
	sockets command and cause GDM to stop managing future displays.
Comment 1 Alexey Rusakov 2007-08-08 14:27:40 MSD
Ловите 2.18.4-alt1.
Comment 2 Igor Zubkov 2007-08-08 15:41:30 MSD
(In reply to comment #1)
> Ловите 2.18.4-alt1.

А в 4.0?
Comment 3 Alexey Rusakov 2007-08-08 16:20:21 MSD
Насколько я вижу, специфических для GNOME 2.18 зависимостей у gdm нет, посему
можно сразу переложить. GDM вообще существует слегка отдельно от остального
GNOME, в силу своего положения в системе.