CVE-1999-0990: Low severity gnome gdm vulnerability
Error messages generated by gdm with the VerboseAuth setting allows an attacker to identify valid users on a system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the VerboseAuth setting in GDM so error messages do not reveal valid usernames; set VerboseAuth to false in the GDM configuration.
SUSE GDM VerboseAuth = false
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0990?
CVE-1999-0990 is considered a moderate severity vulnerability due to the potential exposure of valid usernames.
How do I fix CVE-1999-0990?
To mitigate CVE-1999-0990, disable the VerboseAuth option in the GDM configuration.
Which software is affected by CVE-1999-0990?
CVE-1999-0990 specifically affects gdm version 2.0_beta4.
What type of vulnerability is CVE-1999-0990?
CVE-1999-0990 is a user enumeration vulnerability that allows attackers to identify valid users on the system.
What are the potential impacts of CVE-1999-0990?
The main impact of CVE-1999-0990 is that it can lead to unauthorized access attempts by providing attackers with valid usernames.