CVE-2015-8316 Information

Description

Array index error in LightDM (aka Light Display Manager) 1.14.3 1.16.x before 1.16.6 when the XDMCP server is enabled allows remote attackers to cause a denial of service (process crash) via an XDMCP request packet with no address.

CVSS Vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Reference

http://www.openwall.com/lists/oss-security/2015/11/22/1 https://bugs.launchpad.net/lightdm/+bug/1516831 https://bugzilla.redhat.com/show_bug.cgi?id=1284574

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

HIGH

Base Severity

5.9

Share on: