CVE-2003-0794: Low severity gnome gdm vulnerability
Published Oct 21, 2003
·Updated
GDM 2.4.4.x before 2.4.4.4, and 2.4.1.x before 2.4.1.7, does not limit the number or duration of commands and uses a blocking socket connection, which allows attackers to cause a denial of service (resource exhaustion) by sending commands and not reading the results.
Affected Software
9 affected components
Gnome gdm=2.4.1
Gnome gdm=2.4.4
Gnome gdm=2.4.1.5
Gnome gdm=2.4.1.2
Gnome gdm=2.4.1.4
Gnome gdm=2.2.5.4
Gnome gdm=2.4.1.3
Gnome gdm=2.4.1.6
Gnome gdm=2.4.1.1
Remediation
Patch Available
Event History
Oct 21, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Nov 17, 2003
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0794?
CVE-2003-0794 has a severity rating that indicates it could lead to denial of service due to resource exhaustion.
2
How do I fix CVE-2003-0794?
To fix CVE-2003-0794, update GDM to versions 2.4.4.4 or later, or 2.4.1.7 or later.
3
What are the affected versions for CVE-2003-0794?
CVE-2003-0794 affects GDM versions 2.4.4.x before 2.4.4.4 and 2.4.1.x before 2.4.1.7.
4
What type of vulnerability is CVE-2003-0794?
CVE-2003-0794 is a denial of service vulnerability that exploits blocking socket connections.
5
Can CVE-2003-0794 be exploited remotely?
Yes, CVE-2003-0794 can be exploited remotely by sending commands that the server does not handle properly.