GNOME gdm XDMCP缓冲区溢出漏洞

漏洞信息详情

GNOME gdm XDMCP缓冲区溢出漏洞

漏洞简介

GNOME gdm,KDE kdm和wdm 的XDMCP解析代码存在缓冲区溢出漏洞。远程攻击者借助超长FORWARD_QUERY请求可以执行任意命令或导致拒绝服务。

漏洞公告

Changing the contents of the ‘Enable’ variable to 0 in the gdm configuration file (often /etc/X11/gdm/gdm.conf) will eliminate this vulnerability.
Update available:

参考网址

来源: CALDERA
名称: CSSA-2000-013.0
链接:ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-013.0.txt

来源: BID
名称: 1370
链接:http://www.securityfocus.com/bid/1370

来源: BID
名称: 1279
链接:http://www.securityfocus.com/bid/1279

来源: BID
名称: 1233
链接:http://www.securityfocus.com/bid/1233

来源: SUSE
名称: 20000524 Security hole in gdm <= 2.0beta4-25
链接:http://www.novell.com/linux/security/advisories/suse_security_announce_49.html

来源: BUGTRAQ
名称: 20000607 Conectiva Linux Security Announcement – gdm
链接:http://archives.neohapsis.com/archives/bugtraq/2000-06/0025.html

来源: BUGTRAQ
名称: 20000521 “gdm” remote hole
链接:http://archives.neohapsis.com/archives/bugtraq/2000-05/0241.html

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享