PT-1999-1888 · Caldera/Mandrake · Kdm
Published
1999-08-22
·
Updated
2017-10-10
·
CVE-2000-0374
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
kdm in Caldera and Mandrake Linux (affected versions not specified)
Description
The default configuration of kdm allows XDMCP connections from any host. This enables remote attackers to obtain sensitive information or bypass additional access restrictions.
Recommendations
For kdm in Caldera and Mandrake Linux, consider restricting XDMCP connections to only trusted hosts as a temporary workaround until a more permanent solution is available. Restrict access to the XDMCP service to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kdm