CVE-2013-4132
published 2013-09-16CVE-2013-4132: KDE-Workspace 4.10.5 and earlier does not properly handle the return value of the glibc 2.17 crypt and pw_encrypt functions, which allows remote attackers to…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.41%
82.5th percentile
KDE-Workspace 4.10.5 and earlier does not properly handle the return value of the glibc 2.17 crypt and pw_encrypt functions, which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via (1) an invalid salt or a (2) DES or (3) MD5 encrypted password, when FIPS-140 is enable, to KDM or an (4) invalid password to KCheckPass.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| kde | kde-workspace | <= 4.10.5 | — |
| kde | kde_sc | <= 4.10.5 | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4vrh-wr8w-rqg2: KDE-Workspace 4
ghsa_unreviewed·2022-05-14
CVE-2013-4132 [MEDIUM] GHSA-4vrh-wr8w-rqg2: KDE-Workspace 4
KDE-Workspace 4.10.5 and earlier does not properly handle the return value of the glibc 2.17 crypt and pw_encrypt functions, which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via (1) an invalid salt or a (2) DES or (3) MD5 encrypted password, when FIPS-140 is enable, to KDM or an (4) invalid password to KCheckPass.
Red Hat
kde-workspace: NULL pointer dereference in KDM and KCheckPass when glibc 2.17 or FIPS-140 enabled system used
vendor_redhat·2013-06-29·CVSS 5.0
CVE-2013-4132 [MEDIUM] CWE-476 kde-workspace: NULL pointer dereference in KDM and KCheckPass when glibc 2.17 or FIPS-140 enabled system used
kde-workspace: NULL pointer dereference in KDM and KCheckPass when glibc 2.17 or FIPS-140 enabled system used
KDE-Workspace 4.10.5 and earlier does not properly handle the return value of the glibc 2.17 crypt and pw_encrypt functions, which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via (1) an invalid salt or a (2) DES or (3) MD5 encrypted password, when FIPS-140 is enable, to KDM or an (4) invalid password to KCheckPass.
Statement: Not Vulnerable. This issue does not affect the version of kdebase package as shipped with Red Hat Enterprise Linux 5. This issue does not affect the version of kdebase-workspace package as shipped with Red Hat Enterprise Linux 6.
Package: kdebase (Red Hat Enterprise Linux 5) - Not affected
Package: kdebase-work
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-updates/2013-07/msg00082.htmlhttp://lists.opensuse.org/opensuse-updates/2013-08/msg00002.htmlhttp://seclists.org/oss-sec/2013/q3/117http://seclists.org/oss-sec/2013/q3/120https://git.reviewboard.kde.org/r/111261/http://lists.opensuse.org/opensuse-updates/2013-07/msg00082.htmlhttp://lists.opensuse.org/opensuse-updates/2013-08/msg00002.htmlhttp://seclists.org/oss-sec/2013/q3/117http://seclists.org/oss-sec/2013/q3/120https://git.reviewboard.kde.org/r/111261/
2013-09-16
Published