Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

XDM Session Cookie Guessing Vulnerability

xdm is the X Display Manager, a component of the XFree86 package. xdm manages the display of X sessions both locally and remotely.

An xdm server compiled without WrapHelp.c is vulnerable to a brute force X cookie attack, due to using trivially guessed numbers to secure the session, via gettimeofday().

This makes it possible for a remote user to potentially gain access to the display.







 

Privacy Statement
Copyright 2008, SecurityFocus