First published: Fri May 11 2007(Updated: )
Description of problem: gdm used to be built with tcp_wrappers on previous RHEL releases, although the BuildRequires was missing there as well. The tcp_wrappers package just happened to appear in the buildroot. I believe it's nice to be able to limit XDMCP connections using hosts.{allow,deny}. Version-Release number of selected component (if applicable): gdm-2.16.0-30.el5 Additional info: If you're going to fix this, don't forget that <a class="bz_bug_link bz_status_CLOSED bz_closed bz_public " title="CLOSED ERRATA - CVE-2007-5079 gdm with xdmcp ignoring tcp_wrappers on x86_64" href="show_bug.cgi?id=181302">bug 181302</a> applies here as well.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNOME gdm | <=2.16 | |
GNOME gdm | =0.7 | |
GNOME gdm | =1.0 | |
GNOME gdm | =2.0 | |
GNOME gdm | =2.2 | |
GNOME gdm | =2.3 | |
GNOME gdm | =2.4 | |
GNOME gdm | =2.5 | |
GNOME gdm | =2.6 | |
GNOME gdm | =2.8 | |
GNOME gdm | =2.13 | |
GNOME gdm | =2.14 | |
GNOME gdm | =2.15 | |
Redhat Enterprise Linux | =5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.