CVE-2000-0491: Buffer Overflow

Published May 24, 2000
·
Updated

Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of service via a long FORWARDQUERY request.

Affected Software

4 affected components
Gnome gdm=1.0
Caldera OpenLinux
SUSE SuSE Linux=6.2
SUSE SuSE Linux=6.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove GNOME gdm from your environment.

    Uninstall gdm if remote graphical login/display manager functionality is not required.

  2. Remove

    Remove KDE kdm from your environment.

    Uninstall kdm if remote graphical login/display manager functionality is not required.

  3. Remove

    Remove wdm from your environment.

    Uninstall wdm if remote graphical login/display manager functionality is not required.

  4. Configuration

    Disable XDMCP/remote X11 login support in gdm to prevent processing of FORWARD_QUERY requests.

    GNOME gdm XDMCP (FORWARD_QUERY) handling = disabled
  5. Configuration

    Disable XDMCP/remote X11 login support in kdm to prevent processing of FORWARD_QUERY requests.

    KDE kdm XDMCP (FORWARD_QUERY) handling = disabled
  6. Configuration

    Disable XDMCP/remote X11 login support in wdm to prevent processing of FORWARD_QUERY requests.

    wdm XDMCP (FORWARD_QUERY) handling = disabled
  7. Compensating control

    Block or filter XDMCP traffic (UDP port 177) at network perimeter devices and restrict access to display manager services to trusted hosts/networks.

Event History

May 24, 2000
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Jul 12, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2000-0491?

CVE-2000-0491 is classified as a high severity vulnerability due to the potential for remote command execution and denial of service.

2

How do I fix CVE-2000-0491?

To fix CVE-2000-0491, update the affected software packages to their latest versions that contain the patched XDMCP parsing code.

3

Which software is affected by CVE-2000-0491?

CVE-2000-0491 affects GNOME gdm 1.0, SUSE Linux versions 6.2 and 6.4, as well as SCO OpenLinux Server.

4

Can CVE-2000-0491 be exploited remotely?

Yes, CVE-2000-0491 can be exploited remotely through a long FORWARD_QUERY request to the vulnerable software.

5

What are the consequences of CVE-2000-0491 exploitation?

Exploitation of CVE-2000-0491 can lead to arbitrary command execution or a denial of service on the affected systems.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203