First published: Thu Jun 03 2004(Updated: )
XDM in XFree86 opens a chooserFd TCP socket even when DisplayManager.requestPort is 0, which could allow remote attackers to connect to the port, in violation of the intended restrictions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
X.org X.org | =6.7.0 | |
XFree86 | =cvs | |
Gentoo Linux | =1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0419 is considered a moderate severity vulnerability due to the unauthorized remote access it allows.
To fix CVE-2004-0419, ensure that DisplayManager.requestPort is correctly set to 0 or apply vendor patches that resolve this issue.
The impact of CVE-2004-0419 includes potential unauthorized remote connections to the XDM service, leading to possible exploitation.
CVE-2004-0419 affects XFree86 version 6.7.0, XDM from the CVS repository, and Gentoo Linux version 1.4.
CVE-2004-0419 can be exploited by remote attackers who can connect to the open chooserFd TCP socket.