CVE-2013-4143
Last modified
CVE-2013-4143 is a vulnerability of currently unknown severity. The (1) checkPasswd and (2) checkGroupXlockPasswds functions in xlockmore before 5.43 do not properly handle when a NULL value is returned upon an error by the crypt or dispcrypt function as implemented in glibc 2.17 and later, which allows attackers to bypass the screen lock via vectors related to invalid salts.. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
The (1) checkPasswd and (2) checkGroupXlockPasswds functions in xlockmore before 5.43 do not properly handle when a NULL value is returned upon an error by the crypt or dispcrypt function as implemented in glibc 2.17 and later, which allows attackers to bypass the screen lock via vectors related to invalid salts.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| David Bagley | Xlockmore | <= 5.42 |
| David Bagley | Xlockmore | 5.24 |
| David Bagley | Xlockmore | 5.25 |
| David Bagley | Xlockmore | 5.26 |
| David Bagley | Xlockmore | 5.27 |
| David Bagley | Xlockmore | 5.28 |
| David Bagley | Xlockmore | 5.29 |
| David Bagley | Xlockmore | 5.30 |
| David Bagley | Xlockmore | 5.31 |
| David Bagley | Xlockmore | 5.32 |
| David Bagley | Xlockmore | 5.33 |
| David Bagley | Xlockmore | 5.34 |
| David Bagley | Xlockmore | 5.35 |
| David Bagley | Xlockmore | 5.36 |
| David Bagley | Xlockmore | 5.37 |
| David Bagley | Xlockmore | 5.38 |
| David Bagley | Xlockmore | 5.39 |
| David Bagley | Xlockmore | 5.40 |
| David Bagley | Xlockmore | 5.41 |
References
- http://www.tux.org/~bagleyd/xlock/xlockmore.READMEVendor Advisory
- http://www.tux.org/~bagleyd/xlock/xlockmore.READMEVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-4143?
How severe is CVE-2013-4143?
How do I fix CVE-2013-4143?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-4137Multiple SQL injection vulnerabilities in StatusNet 1.0 befo…
- CVE-2013-4138Cross-site scripting (XSS) vulnerability in the Hatch theme …
- CVE-2013-4139The Stage File Proxy module 7.x-1.x before 7.x-1.4 for Drupa…
- CVE-2013-4140Cross-site scripting (XSS) vulnerability in the TinyBox (Sim…
- CVE-2013-4141Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2013-4142Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2013-4144There is an object injection vulnerability in swfupload plug…9.8
- CVE-2013-4145Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2013-4146Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2013-4147Multiple format string vulnerabilities in Yet Another Radius…
- CVE-2013-4148Integer signedness error in the virtio_net_load function in …
- CVE-2013-4149Buffer overflow in virtio_net_load function in net/virtio-ne…
Are you affected by CVE-2013-4143?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
