CVE Vulnerabilities

CVE-2009-2697

Improper Authentication

Published: Sep 04, 2009 | Modified: Sep 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
4.3 LOW
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
NEGLIGIBLE

The Red Hat build script for the GNOME Display Manager (GDM) before 2.16.0-56 on Red Hat Enterprise Linux (RHEL) 5 omits TCP Wrapper support, which might allow remote attackers to bypass intended access restrictions via XDMCP connections, a different vulnerability than CVE-2007-5079.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Gdm Gnome * 2.16 (including)
Gdm Gnome 0.7 (including) 0.7 (including)
Gdm Gnome 1.0 (including) 1.0 (including)
Gdm Gnome 2.0 (including) 2.0 (including)
Gdm Gnome 2.2 (including) 2.2 (including)
Gdm Gnome 2.3 (including) 2.3 (including)
Gdm Gnome 2.4 (including) 2.4 (including)
Gdm Gnome 2.5 (including) 2.5 (including)
Gdm Gnome 2.6 (including) 2.6 (including)
Gdm Gnome 2.8 (including) 2.8 (including)
Gdm Gnome 2.13 (including) 2.13 (including)
Gdm Gnome 2.14 (including) 2.14 (including)
Gdm Gnome 2.15 (including) 2.15 (including)
Red Hat Enterprise Linux 5 RedHat gdm-1:2.16.0-56.el5 *

Potential Mitigations

References