vendor:
gdm
by:
Chris Evans
7.5
CVSS
HIGH
Buffer Overrun
120
CWE
Product Name: gdm
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Buffer Overrun in XDMCP Handling Code in gdm
A buffer overrun exists in the XDMCP handling code used in 'gdm', an xdm replacement, shipped as part of the GNOME desktop. By sending a maliciously crafted XDMCP message, it is possible for a remote attacker to execute arbitrary commands as root on the susceptible machine. The problem lies in the handling of the display information sent as part of an XDMCP 'FORWARD_QUERY' request.
Mitigation:
The vulnerability can be mitigated by ensuring that gdm is not configured to listen via XDMCP. If the "Enable" variable in the /etc/X11/gdm/gdm.conf file is set to 0, the system is not susceptible to this vulnerability.