CVE-2007-5079: Medium severity redhat Linux vulnerability
From Bugzilla Helper: User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; iOpus-I-M; SV1)
Description of problem: The x8664 bit version of AS4 (fully patched) appears to ignore tcpwrappers completely when using gdm with XDMCP. The 32 bit version of AS4 works perfectly so this bug appears to be restricted to the 64bit version. I suspect the problem with the wrappers on the 64 bit version may be a bit more general than just XDMCP access as I tested a telnet server and while the wrappers are not completely ignored connections are not refused cleanly (You donât get the login prompt but you are still hooked up to the machine). The 32 bit version again works perfectly.
Version-Release number of selected component (if applicable): tcpwrappers
How reproducible: Always
Steps to Reproduce: 1. Instll the OS 2. Configure gdmsetup to allow remote XDMCP conectivity 3. configure hosts.deny to restrict conections all:all
Actual Results: no restriction to remote desktop
Expected Results: remote desktop should have been refused
Additional info:
Other sources
Red Hat Enterprise Linux 4 does not properly compile and link gdm with tcpwrappers on x8664 platforms, which might allow remote attackers to bypass intended access restrictions.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5079?
CVE-2007-5079 is considered to be medium severity due to the potential for remote attackers to bypass access restrictions.
How do I fix CVE-2007-5079?
To fix CVE-2007-5079, you should update the gdm package to version 1:2.6.0.5-7.rhel4.19.e or later.
What versions of Red Hat are affected by CVE-2007-5079?
CVE-2007-5079 affects Red Hat Enterprise Linux 4, specifically on x86_64 platforms.
Can CVE-2007-5079 be exploited remotely?
Yes, CVE-2007-5079 can be exploited remotely by attackers to bypass intended access restrictions.
Is there a specific patch for CVE-2007-5079?
Yes, the specific remedy for CVE-2007-5079 is included in the package update for gdm.