CVE-2001-0191: Buffer Overflow
Published May 3, 2001
·Updated
gnuserv before 3.12, as shipped with XEmacs, does not properly check the specified length of an X Windows MIT-MAGIC-COOKIE cookie, which allows remote attackers to execute arbitrary commands via a buffer overflow, or brute force authentication by using a short cookie length.
Affected Software
3 affected components
Andy Norman Gnuserv<=3.11
All of the following
Andynorman Gnuserv<3.12
GNU XEmacs
Remediation
Patch Available
Patch Available
Event History
May 3, 2001
CVE Published
04:00 AM
May 7, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0191?
CVE-2001-0191 is considered a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2001-0191?
To fix CVE-2001-0191, upgrade Gnuserv to version 3.12 or later.
3
What impact does CVE-2001-0191 have on my system?
CVE-2001-0191 can allow attackers to execute arbitrary commands on the affected system.
4
Which versions of Gnuserv are affected by CVE-2001-0191?
Gnuserv versions before 3.12 are vulnerable to CVE-2001-0191.
5
Is XEmacs vulnerable to CVE-2001-0191?
XEmacs itself is not vulnerable, but the bundled Gnuserv prior to version 3.12 is.