First published: Tue Aug 10 2004(Updated: )
X Display Manager (XDM) on Solaris 8 allows remote attackers to cause a denial of service (XDM crash) via an invalid X Display Manager Control Protocol (XDMCP) request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun SunOS | =5.7 | |
Sun SunOS | =5.8 | |
Oracle Solaris and Zettabyte File System (ZFS) | =9.0 | |
Oracle Solaris and Zettabyte File System (ZFS) | =7.0 | |
Oracle Solaris and Zettabyte File System (ZFS) | =9.0 | |
Oracle Solaris and Zettabyte File System (ZFS) | =9.0-x86_update_2 | |
Oracle Solaris and Zettabyte File System (ZFS) | =8.0 | |
Oracle Solaris and Zettabyte File System (ZFS) | =7.0 | |
Oracle Solaris and Zettabyte File System (ZFS) | =8.0 | |
Oracle Solaris and Zettabyte File System (ZFS) | =9.0 | |
Oracle Solaris and Zettabyte File System (ZFS) | =9.0 | |
Oracle Solaris and Zettabyte File System (ZFS) | =9.0-x86_update_2 | |
Sun SunOS | =5.7 | |
Sun SunOS | =5.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1347 is classified as a denial of service vulnerability due to the potential for XDM crash.
To mitigate CVE-2004-1347, ensure that your X Display Manager (XDM) is updated to a fixed version that addresses the vulnerability.
CVE-2004-1347 affects Solaris 7, 8, and 9 versions of the X Display Manager (XDM) installed on various architectures.
CVE-2004-1347 involves remote attackers exploiting invalid XDMCP requests to crash the X Display Manager.
Versions of Solaris older than 7 or any non-affected versions such as 7.0 are not vulnerable to CVE-2004-1347.