PT-2003-1070 · Gnome · Gdm

George

·

Published

2003-08-21

·

Updated

2017-10-11

·

CVE-2003-0548

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions gdm versions prior to 2.4.1.6
Description The issue affects the X Display Manager Control Protocol (XDMCP) support for GDM, allowing attackers to cause a denial of service (daemon crash) when a chosen host expires. This can be exploited remotely, potentially leading to disruption of protected information availability.
Recommendations For versions prior to 2.4.1.6, update to version 2.4.1.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the XDMCP protocol to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-07974
BDU:2015-07975
CVE-2003-0548

Affected Products

Gdm