PT-1999-1888 · Caldera/Mandrake · Kdm

Published

1999-08-22

·

Updated

2017-10-10

·

CVE-2000-0374

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions kdm in Caldera and Mandrake Linux (affected versions not specified)
Description The default configuration of kdm allows XDMCP connections from any host. This enables remote attackers to obtain sensitive information or bypass additional access restrictions.
Recommendations For kdm in Caldera and Mandrake Linux, consider restricting XDMCP connections to only trusted hosts as a temporary workaround until a more permanent solution is available. Restrict access to the XDMCP service to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2000-0374

Affected Products

Kdm