CVE Vulnerabilities

CVE-2001-1086

Published: Jul 04, 2001 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote attackers to gain unauthorized access to the X display via a brute force attack.

Affected Software

NameVendorStart VersionEnd Version
X11r6Xfree86_project3.3 (including)3.3 (including)
X11r6Xfree86_project3.3.3 (including)3.3.3 (including)

References