7.5
CVSSv2

CVE-2001-1086

Published: 04/07/2001 Updated: 19/12/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote malicious users to gain unauthorized access to the X display via a brute force attack.

Vulnerable Product Search on Vulmon Subscribe to Product

xfree86 project x11r6 3.3

xfree86 project x11r6 3.3.3

Exploits

source: wwwsecurityfocuscom/bid/2985/info xdm is the X Display Manager, a component of the XFree86 package xdm manages the display of X sessions both locally and remotely An xdm server compiled without WrapHelpc is vulnerable to a brute force X cookie attack, due to using trivially guessed numbers to secure the session, via gettimeofd ...