CVE-2004-1347: Medium severity Sun SunOS vulnerability
Published Aug 10, 2004
·Updated
X Display Manager (XDM) on Solaris 8 allows remote attackers to cause a denial of service (XDM crash) via an invalid X Display Manager Control Protocol (XDMCP) request.
Affected Software
14 affected components
Sun SunOS=5.7
Sun SunOS=5.8
Sun Solaris=9.0
Sun Solaris=7.0
Sun Solaris=9.0
Sun Solaris=9.0-x86_update_2
Sun Solaris=8.0
Sun Solaris=7.0
Sun Solaris=8.0
Sun Solaris=9.0
Sun Solaris=9.0
Sun Solaris=9.0-x86_update_2
Sun SunOS=5.7
Sun SunOS=5.8
Remediation
Patch Available
Patch Available
Patch Available
Event History
Aug 10, 2004
CVE Published
04:00 AM
Jan 19, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1347?
CVE-2004-1347 is classified as a denial of service vulnerability due to the potential for XDM crash.
2
How do I fix CVE-2004-1347?
To mitigate CVE-2004-1347, ensure that your X Display Manager (XDM) is updated to a fixed version that addresses the vulnerability.
3
Which systems are affected by CVE-2004-1347?
CVE-2004-1347 affects Solaris 7, 8, and 9 versions of the X Display Manager (XDM) installed on various architectures.
4
What type of attack does CVE-2004-1347 involve?
CVE-2004-1347 involves remote attackers exploiting invalid XDMCP requests to crash the X Display Manager.
5
Is my version of Solaris safe from CVE-2004-1347?
Versions of Solaris older than 7 or any non-affected versions such as 7.0 are not vulnerable to CVE-2004-1347.