CVE-2013-2179
Last modified
CVE-2013-2179 is a vulnerability of currently unknown severity. X.Org xdm 1.1.10, 1.1.11, and possibly other versions, when performing authentication using certain implementations of the crypt API function that can return NULL, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by attempting to log into an account whose password field contains invalid characters, as demonstrated using the crypt function from glibc 2.17 and later with (1) the "!" character in the salt portion of a password field or (2) a password that has been encrypted using DES or MD5 in FIPS-140 mode.. EPSS estimates a 2.44% chance of exploitation in the next 30 days.
Description
X.Org xdm 1.1.10, 1.1.11, and possibly other versions, when performing authentication using certain implementations of the crypt API function that can return NULL, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by attempting to log into an account whose password field contains invalid characters, as demonstrated using the crypt function from glibc 2.17 and later with (1) the "!" character in the salt portion of a password field or (2) a password that has been encrypted using DES or MD5 in FIPS-140 mode.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| X | X Display Manager | 1.1.10 |
| X | X Display Manager | 1.1.11 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-2179?
How severe is CVE-2013-2179?
How do I fix CVE-2013-2179?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-2173wp-includes/class-phpass.php in WordPress 3.5.1, when a pass…
- CVE-2013-2174Heap-based buffer overflow in the curl_easy_unescape functio…
- CVE-2013-2175HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when con…
- CVE-2013-2176Unquoted Windows search path vulnerability in the Red Hat En…
- CVE-2013-2177Cross-site scripting (XSS) vulnerability in the Display Suit…
- CVE-2013-2178The apache-auth.conf, apache-nohome.conf, apache-noscript.co…
- CVE-2013-2180Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: T…
- CVE-2013-2181Cross-site scripting (XSS) vulnerability in the Directory Li…
- CVE-2013-2182The Mandril security plugin in Monkey HTTP Daemon (monkeyd) …
- CVE-2013-2183Monkey HTTP Daemon has local security bypass7.1
- CVE-2013-2184Movable Type before 5.2.6 does not properly use the Storable…
- CVE-2013-2185The readObject method in the DiskFileItem class in Apache To…
Are you affected by CVE-2013-2179?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
