First published: Wed Jul 04 2001(Updated: )
XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote attackers to gain unauthorized access to the X display via a brute force attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
XFree86 X Server | =3.3 | |
XFree86 X Server | =3.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1086 is considered to have a moderate severity due to its potential for unauthorized access to the X display.
To fix CVE-2001-1086, upgrade to a version of XFree86 that does not generate easily guessable cookies.
CVE-2001-1086 affects XFree86 X Server versions 3.3 and 3.3.3 when compiled with the HasXdmXauth option.
CVE-2001-1086 allows unauthorized access via easily guessable cookies that can be brute-forced by attackers.
There is no specific patch for CVE-2001-1086; the recommended action is to upgrade to a secure version of XFree86.