« Volver al listado

CVE-2015-8316

Estado: ModificadaMedia (5.9)—

Array index error in LightDM (aka Light Display Manager) 1.14.3, 1.16.x before 1.16.6 when the XDMCP server is enabled allows remote attackers to cause a denial of service (process crash) via an XDMCP request packet with no address.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-8316",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 5.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "security@debian.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-09-06T21:29:01.067",
  "references": [
    {
      "url": "http://www.openwall.com/lists/oss-security/2015/11/22/1",
      "tags": [
        "Mailing List",
        "VDB Entry"
      ],
      "source": "security@debian.org"
    },
    {
      "url": "https://bugs.launchpad.net/lightdm/+bug/1516831",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "security@debian.org"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1284574",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "security@debian.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2015/11/22/1",
      "tags": [
        "Mailing List",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugs.launchpad.net/lightdm/+bug/1516831",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1284574",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-129"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Array index error in LightDM (aka Light Display Manager) 1.14.3, 1.16.x before 1.16.6 when the XDMCP server is enabled allows remote attackers to cause a denial of service (process crash) via an XDMCP request packet with no address."
    },
    {
      "lang": "es",
      "value": "Un error de índice de array en LightDM (también llamado Light Display Manager) en sus versiones 1.14.3, 1.16.x y anteriores a 1.16.6, cuando el servidor XDMCP está habilitado, permite que atacantes remotos provoquen una denegación de servicio (bloqueo del proceso) utilizando un paquete de peticiones XDMCP sin dirección."
    }
  ],
  "lastModified": "2026-06-17T00:34:18.423",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:lightdm_project:lightdm:1.14.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BB9B548D-EA70-4B95-99BC-83E27A564F79"
            },
            {
              "criteria": "cpe:2.3:a:lightdm_project:lightdm:1.16:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "034FA2A3-B11F-4066-91AB-F9B027A6A085"
            },
            {
              "criteria": "cpe:2.3:a:lightdm_project:lightdm:1.16.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "619A9D1D-36A3-4DA9-95A5-5BD51DE131EE"
            },
            {
              "criteria": "cpe:2.3:a:lightdm_project:lightdm:1.16.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D9D7ADBF-8F5F-4048-93BF-51736E2D2A10"
            },
            {
              "criteria": "cpe:2.3:a:lightdm_project:lightdm:1.16.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "53953612-ACFF-44E1-9921-CAC9C297B7E8"
            },
            {
              "criteria": "cpe:2.3:a:lightdm_project:lightdm:1.16.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "686C89D4-5C3B-4003-AB1C-836E9718F320"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@debian.org"
}