Bugzilla – Bug 829859
VUL1: CVE-2013-4143: xlockmore: NULL ptr deref
Last modified: 2013-07-22 06:11:08 UTC
Via oss-sec: To: oss-security From: mancha Hello Kurt, vendors, et al. xlockmore 5.43 released 2 days ago with a fix for a security flaw related to potential NULL pointer dereferences when authenticating via glibc 2.17+ crypt() and OSF/1 C2 security's dispcrypt(). Under certain conditions the NULL pointers can trigger a crash in xlockmore effectively bypassing the screen lock. [1] http://www.tux.org/~bagleyd/xlock/xlockmore.README --mancha
http://sourceforge.net/projects/miscellaneouspa/files/glibc217/xlockmore-5.42-glibc217-crypt.diff
bugbot adjusting priority
CVE-2013-4143
Should I fix it only for distros with glibc-2.17 (openSUSE 12.3 and Factory) or for all distros which have the affected code?
Do opensuse factory. I do not think we even use the crypt codepath at all, as we configure the unix2_checkpass helper binary to do checking.
This is an autogenerated message for OBS integration: This bug (829859) was mentioned in https://build.opensuse.org/request/show/183772 Factory / xlockmore
should be done then