SECURITY: gdm local DoS vulnerability

Ximian Distribution <[email protected]> Thu, 16 Oct 2003 20:33:53 -0400
Newsgroups gmane.comp.gnome.ximian.updates
Message-ID <1066350833.1870.14.camel@boatswain>
Severity: Security
Product: XD2: gdm
References:
 CAN-2003-0793
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0793
 CAN-2003-0794
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0794

gdm 2.4.1.6 as released was vulnerable to two local denial of service
attacks, classified as CAN-2003-0793 and CAN-2003-0794. These
vulnerabilities primarily affect public workstations such as those found
in libraries, computer labs, and web kiosks and allowed a malicious
local user to crash the daemon, rendering further logins through gdm
impossible.   Answer   A new version of gdm has been released, and
Ximian has released updated gdm packages for XD2 which are patched to
fix the local denial of service vulnerabilities. Administrators may wish
to upgrade to the new packages using Red Carpet or rug, or from our FTP
site.

Red Hat Linux 7.3
ftp://ftp.ximian.com/pub/xd2/redhat-73-i386/gdm-2.4.1.6-0.ximian.4.2.i386.rpm

Red Hat Linux 8.0
ftp://ftp.ximian.com/pub/xd2/redhat-80-i386/gdm-2.4.1.6-0.ximian.5.2.i386.rpm

Red Hat Linux 9
ftp://ftp.ximian.com/pub/xd2/redhat-9-i386/gdm-2.4.1.6-0.ximian.6.2.i386.rpm

SuSE Linux 8.2
ftp://ftp.ximian.com/pub/xd2/suse-82-i586/gdm2-2.4.1.6-0.ximian.7.2.i586.rpm

_______________________________________________
updates maillist  -  [email protected]
To unsubscribe from this list, or to change your subscription options, follow the link below:
http://lists.ximian.com/mailman/listinfo/updates