CVE-2000-1071: Critical severity Netscape Iplanet Ical vulnerability
Published Dec 11, 2000
·Updated
The GUI installation for iCal 2.1 Patch 2 disables access control for the X server using an "xhost +" command, which allows remote attackers to monitor X Windows events and gain privileges.
Affected Software
1 affected component
Netscape Iplanet Ical=2.1-patch2
Remediation
Event History
Dec 11, 2000
CVE Published
05:00 AM
Jan 22, 2001
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-1071?
CVE-2000-1071 is considered a high-severity vulnerability due to the potential for remote attackers to gain unauthorized access to X Windows events.
2
How do I fix CVE-2000-1071?
To fix CVE-2000-1071, disable the 'xhost +' command and implement proper access control measures for the X server.
3
What software is affected by CVE-2000-1071?
CVE-2000-1071 affects iPlanet iCal version 2.1 with Patch 2.
4
What are the risks of not addressing CVE-2000-1071?
Not addressing CVE-2000-1071 allows remote attackers to monitor sensitive X Windows events and potentially gain higher privileges.
5
Can CVE-2000-1071 be exploited remotely?
Yes, CVE-2000-1071 can be exploited remotely due to the improper disabling of X server access controls.