PT-2000-1968 · Mandrake · Mandrake Linux

Publicado

2000-12-11

·

Atualizado

2017-10-10

·

CVE-2000-1059

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mandrake Linux versions 7.0 through 7.1
Description The default configuration of the Xsession file bypasses the Xauthority access control mechanism with an "xhost + localhost" command. This allows local users to sniff X Windows events and gain privileges.
Recommendations For Mandrake Linux versions 7.0 through 7.1, consider modifying the Xsession file to remove the "xhost + localhost" command to prevent bypassing the Xauthority access control mechanism. As a temporary workaround, restrict access to the X Windows system to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2000-1059

Produtos afetados

Mandrake Linux