XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote attackers to gain unauthorized access to the X display via a brute force attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
X11r6 | Xfree86_project | 3.3 (including) | 3.3 (including) |
X11r6 | Xfree86_project | 3.3.3 (including) | 3.3.3 (including) |