Note:
This project will be discontinued after December 13, 2021. [more]
2009-09-04
The Red Hat build script for the GNOME Display Manager (GDM) before 2.16.0-56 on Red Hat Enterprise Linux (RHEL) 5 omits TCP Wrapper support, which might allow remote attackers to bypass intended access restrictions via XDMCP connections, a different vulnerability than CVE-2007-5079.
Products | Gdm |
Type | Improper Authentication (CWE-287) |
First patch | - None (likely due to unavailable code) |
Links |
• http://secunia.com/advisories/36553
• http://www.securityfocus.com/bid/36219 • https://bugzilla.redhat.com/show_bug.cgi?id=239818 • https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9586 • https://rhn.redhat.com/errata/RHSA-2009-1364.html |