SUSE-SU-2018:2771-1
Dashboard / Vulnerabilities / SUSE-SU-2018:2771-1
SUSE-SU-2018:2771-1
Summary: Security update for gdm
Details: This update for gdm provides the following fixes: This security issue was fixed: - CVE-2018-14424: The daemon in GDM did not properly unexport display objects from its D-Bus interface when they are destroyed, which allowed a local attacker to trigger a use-after-free via a specially crafted sequence of D-Bus method calls, resulting in a denial of service or potential code execution (bsc#1103737) These non-security issues were fixed: - Enable pam_keyinit module (bsc#1081947) - Fix a build race in SLE (bsc#1103093)
References: https://www.suse.com/support/update/announcement/2018/suse-su-20182771-1/, https://bugzilla.suse.com/1081947, https://bugzilla.suse.com/1103093, https://bugzilla.suse.com/1103737, https://www.suse.com/security/cve/CVE-2018-14424
Affected packages
Package
Name: gdm
Purl: pkg:rpm/suse/gdm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015
Affected ranges
Type: ECOSYSTEM
Events:
