CVE Vulnerabilities

CVE-2001-1086

Published: Jul 04, 2001 | Modified: Dec 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote attackers to gain unauthorized access to the X display via a brute force attack.

Affected Software

Name Vendor Start Version End Version
X11r6 Xfree86_project 3.3 3.3
X11r6 Xfree86_project 3.3.3 3.3.3

References