First published: Sun Dec 05 1999(Updated: )
Error messages generated by gdm with the VerboseAuth setting allows an attacker to identify valid users on a system.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE GDM | =2.0_beta4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0990 is considered a moderate severity vulnerability due to the potential exposure of valid usernames.
To mitigate CVE-1999-0990, disable the VerboseAuth option in the GDM configuration.
CVE-1999-0990 specifically affects gdm version 2.0_beta4.
CVE-1999-0990 is a user enumeration vulnerability that allows attackers to identify valid users on the system.
The main impact of CVE-1999-0990 is that it can lead to unauthorized access attempts by providing attackers with valid usernames.