Candidate: CVE-2015-8316 PublicDate: 2017-09-06 21:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8316 http://www.openwall.com/lists/oss-security/2015/11/21/2 Description: Array index error in LightDM (aka Light Display Manager) 1.14.3, 1.16.x before 1.16.6 when the XDMCP server is enabled allows remote attackers to cause a denial of service (process crash) via an XDMCP request packet with no address. Ubuntu-Description: Notes: mdeslaur> introduced in 1.14.3 and 1.15.1 by the following commits: mdeslaur> http://bazaar.launchpad.net/~lightdm-team/lightdm/1.14/revision/2143 mdeslaur> http://bazaar.launchpad.net/~lightdm-team/lightdm/1.16/revision/2155 mdeslaur> fixed in 1.14.4, 1.16.6 and 1.17.2 Bugs: https://bugs.launchpad.net/lightdm/+bug/1516831 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H [5.9 MEDIUM] Patches_lightdm: upstream: https://bazaar.launchpad.net/~lightdm-team/lightdm/1.14/revision/2166 (1.14.x) upstream: https://bazaar.launchpad.net/~lightdm-team/lightdm/1.16/revision/2207 (1.16.x) upstream_lightdm: released (1.14.4,1.16.6,1.17.2) precise_lightdm: not-affected (1.14/1.16 only) trusty_lightdm: not-affected (1.14/1.16 only) trusty/esm_lightdm: DNE (trusty was not-affected [1.14/1.16 only]) vivid_lightdm: not-affected (1.14.2-0ubuntu1.1) vivid/stable-phone-overlay_lightdm: not-affected (1.14.2-0ubuntu1.1) vivid/ubuntu-core_lightdm: DNE wily_lightdm: ignored (reached end-of-life) xenial_lightdm: not-affected (1.17.2-0ubuntu1) esm-infra/xenial_lightdm: not-affected (1.17.2-0ubuntu1) devel_lightdm: not-affected (1.17.2-0ubuntu1)