CVE-2009-2697: Medium severity suse gdm vulnerability
Description of problem: gdm used to be built with tcpwrappers on previous RHEL releases, although the BuildRequires was missing there as well. The tcpwrappers package just happened to appear in the buildroot.
I believe it's nice to be able to limit XDMCP connections using hosts.{allow,deny}.
Version-Release number of selected component (if applicable): gdm-2.16.0-30.el5
Additional info: If you're going to fix this, don't forget that bug 181302 applies here as well.
Other sources
The Red Hat build script for the GNOME Display Manager (GDM) before 2.16.0-56 on Red Hat Enterprise Linux (RHEL) 5 omits TCP Wrapper support, which might allow remote attackers to bypass intended access restrictions via XDMCP connections, a different vulnerability than CVE-2007-5079.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2697?
CVE-2009-2697 is considered a moderate severity vulnerability affecting specific versions of GNOME Display Manager.
How do I fix CVE-2009-2697?
To fix CVE-2009-2697, update to a patched version of the GNOME Display Manager that properly implements tcp_wrappers.
What versions of GNOME Display Manager are affected by CVE-2009-2697?
CVE-2009-2697 affects GNOME Display Manager versions up to 2.16 and specific older versions such as 0.7 to 2.15.
Is CVE-2009-2697 present in Red Hat Enterprise Linux 5?
CVE-2009-2697 is not present in Red Hat Enterprise Linux 5, as it is marked as not vulnerable.
What is the main issue highlighted in CVE-2009-2697?
The main issue in CVE-2009-2697 is the lack of tcp_wrappers support in certain builds of the GNOME Display Manager, which could allow XDMCP connections from unauthorized hosts.