PT-2005-1627 · Nomachine · Freenx

Fabian Franz

·

Published

2005-02-25

·

Updated

2008-09-05

·

CVE-2005-0579

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions FreeNX versions prior to 0.2.8
Description The issue arises from improper handling of the XAUTHORITY environment variable when it is not set, allowing local users to access the X server without X authentication.
Recommendations For versions prior to 0.2.8, update to version 0.2.8 or later to resolve the issue. As a temporary workaround, consider setting the XAUTHORITY environment variable to prevent unauthorized access to the X server.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0579

Affected Products

Freenx