vendor:
XFree86
by:
(ntf & sky)
7.5
CVSS
HIGH
Brute Force X Cookie Attack
287
CWE
Product Name: XFree86
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:x.org:xfree86
Platforms Tested:
2001
XDM Brute Force X Cookie Attack
An xdm server compiled without WrapHelp.c is vulnerable to a brute force X cookie attack, due to using trivially guessed numbers to secure the session, via gettimeofday(). This makes it possible for a remote user to potentially gain access to the display.
Mitigation:
Update the xdm server to a version that includes WrapHelp.c or apply a patch if available. Implement strong session security measures.