CVE-2000-0374: Critical severity caldera openlinux vulnerability

Published Aug 22, 1999
·
Updated

The default configuration of kdm in Caldera and Mandrake Linux, and possibly other distributions, allows XDMCP connections from any host, which allows remote attackers to obtain sensitive information or bypass additional access restrictions.

Affected Software

2 affected components
Caldera OpenLinux=2.2
Caldera OpenLinux=2.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Disable XDMCP in the kdm configuration to prevent accepting XDMCP connections from any host.

    kdm (KDE Display Manager) on SCO OpenLinux Server XDMCP enabled = false
  2. Configuration

    Configure kdm to accept XDMCP connections only from an explicit list of trusted hosts or networks (restrict allowed hosts/networks in the kdm configuration).

    kdm (KDE Display Manager) on SCO OpenLinux Server XDMCP allowed hosts = trusted-hosts-only
  3. Compensating control

    Restrict or block XDMCP (UDP port 177) at network boundaries or host firewalls so only trusted IPs/networks can reach the display manager.

Event History

Aug 22, 1999
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Oct 13, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2000-0374?

CVE-2000-0374 is considered a moderate severity vulnerability due to its potential for unauthorized access to sensitive information.

2

How can I fix CVE-2000-0374?

To fix CVE-2000-0374, configure the kdm settings to restrict XDMCP connections to trusted hosts only.

3

What systems are affected by CVE-2000-0374?

CVE-2000-0374 affects default configurations of kdm in Caldera and Mandrake Linux versions 2.2 and 2.3.

4

What risks does CVE-2000-0374 pose?

CVE-2000-0374 allows remote attackers to obtain sensitive information or bypass access restrictions, leading to potential data exposure.

5

Is CVE-2000-0374 a widespread vulnerability?

CVE-2000-0374 may not be widespread today, but its presence in legacy systems can pose a security risk if not addressed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203