漏洞信息详情
GNOME gdm XDMCP缓冲区溢出漏洞
- CNNVD编号:CNNVD-200005-086
- 危害等级: 超危
- CVE编号:
CVE-2000-0491
- 漏洞类型:
缓冲区溢出
- 发布时间:
2000-05-24
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
gnome - 漏洞来源:
This vulnerability… -
漏洞简介
GNOME gdm,KDE kdm和wdm 的XDMCP解析代码存在缓冲区溢出漏洞。远程攻击者借助超长FORWARD_QUERY请求可以执行任意命令或导致拒绝服务。
漏洞公告
Changing the contents of the ‘Enable’ variable to 0 in the gdm configuration file (often /etc/X11/gdm/gdm.conf) will eliminate this vulnerability.
Update available:
参考网址
来源: CALDERA
名称: CSSA-2000-013.0
链接:ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-013.0.txt
来源: BID
名称: 1370
链接:http://www.securityfocus.com/bid/1370
来源: BID
名称: 1279
链接:http://www.securityfocus.com/bid/1279
来源: BID
名称: 1233
链接:http://www.securityfocus.com/bid/1233
来源: SUSE
名称: 20000524 Security hole in gdm <= 2.0beta4-25
链接:http://www.novell.com/linux/security/advisories/suse_security_announce_49.html
来源: BUGTRAQ
名称: 20000607 Conectiva Linux Security Announcement – gdm
链接:http://archives.neohapsis.com/archives/bugtraq/2000-06/0025.html
来源: BUGTRAQ
名称: 20000521 “gdm” remote hole
链接:http://archives.neohapsis.com/archives/bugtraq/2000-05/0241.html