CVE-2003-0548: Medium severity Gnome gdm vulnerability
Published Aug 22, 2003
·Updated
The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) when a chosen host expires, a different issue than CVE-2003-0549.
Affected Software
22 affected components
Gnome gdm=2.2.0
Gnome gdm=2.4.1
Gnome gdm=2.4.1.1
Gnome gdm=2.4.1.2
Gnome gdm=2.4.1.3
Gnome gdm=2.4.1.4
Gnome gdm=2.4.1.5
Gnome gdm=2.4.1.6
redhat Kdebase=2.0_beta2.45
redhat Kdebase=2.0_beta2.45
redhat Kdebase=2.2.3.1.20
redhat Kdebase=2.2.3.1.20
redhat Kdebase=2.2.3.1.22
redhat Kdebase=2.4.0.7.13
redhat Kdebase=2.4.1.3.5
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Linux Advanced Workstation=2.1
Remediation
Patch Available
Patch Available
Event History
Aug 22, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Aug 27, 2003
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0548?
CVE-2003-0548 is considered a denial of service vulnerability that can lead to a daemon crash.
2
How do I fix CVE-2003-0548?
To mitigate CVE-2003-0548, upgrade GDM to version 2.4.1.6 or later.
3
Which software is affected by CVE-2003-0548?
CVE-2003-0548 affects GDM versions prior to 2.4.1.6 and certain versions of KDE Base.
4
What type of attack is CVE-2003-0548 associated with?
CVE-2003-0548 is associated with a denial of service attack that affects X Display Manager Control Protocol (XDMCP) support.
5
Is CVE-2003-0548 related to any other vulnerabilities?
Yes, CVE-2003-0548 is related to CVE-2003-0549 as both involve issues in GDM, but they exploit different vulnerabilities.