CVE

Id
2069  
CVE No.
CVE-2000-0491  
Status
Candidate  
Description
Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of service via a long FORWARD_QUERY request.  
Phase
Proposed (20000712)  
Votes
MODIFY(2) Frech, Levy | NOOP(2) LeBlanc, Wall | REVIEWING(2) Christey, Ozancin  
Comments
Levy> The BID 1233 vulns is different from the other ones. BID 1233 uses | a FORWARD_QUERY request to overflow an in_addr structure via a memmove | in daemon/xdmcp.c, gdm_xdmcp_handle_forward_query(). In BID 1370 | a buffer is overflowed by a sprintf in xdmcp.c, send_failed(). | Frech> XF:gnome-gdm-bo(4530) | Christey> MANDRAKE:MDKSA-2001:070 | URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-070.php3 | Christey> BUGTRAQ:20000527 gdm exploit | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=96017189021021&w=2 | | Consider REDHAT:RHSA-2000:027 | Christey> RHSA-2000:027 confirmed via Mark Cox