XDM in XFree86 opens a chooserFd TCP socket even when DisplayManager.requestPort is 0, which could allow remote attackers to connect to the port, in violation of the intended restrictions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Xdm | Xfree86_project | cvs | cvs |
X11r6 | X.org | 6.7.0 | 6.7.0 |
Xorg | Ubuntu | dapper | * |
Xorg | Ubuntu | devel | * |
Xorg | Ubuntu | edgy | * |
Xorg | Ubuntu | feisty | * |