Overview
There is a vulnerability in the way Sun Solaris handles invalid X Display Manager Control Protocol (XDMCP) requests. Exploitation of this vulnerability could allow an attacker to cause the X Display Manager (XDM) to crash.
Description
The X Display Manager (xdm(1)) is responsible for managing collections of X displays from local or remote servers using the X Display Manager Control Protocol (XDMCP). The Sun Solaris X Display Manager contains a denial-of-service vulnerability that could be triggered by an invalid XDMCP packet. |
Impact
A remote attacker with the ability to send XDMCP packets to a vulnerable system could cause the X Display Manager to crash. |
Solution
Apply patch Sun has issued an advisory which addresses this issue. For more information on patches available for your system, please refer to Sun Security Alert 57619. |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was reported by Sun Microsystems.
This document was written by Damon Morda.
Other Information
CVE IDs: | None |
Severity Metric: | 4.30 |
Date Public: | 2004-08-09 |
Date First Published: | 2004-08-11 |
Date Last Updated: | 2004-08-11 18:39 UTC |
Document Revision: | 16 |