CVE-2001-1086 Information

Description

XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option which allows remote attackers to gain unauthorized access to the X display via a brute force attack.

Reference

http://online.securityfocus.com/archive/1/195008 http://www.securityfocus.com/archive/1/194907 http://www.securityfocus.com/bid/2985 https://exchange.xforce.ibmcloud.com/vulnerabilities/6808

Share on: