Vulnerabilities > CVE-2001-1086 - Unspecified vulnerability in Xfree86 Project X11R6 3.3/3.3.3
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN xfree86-project
exploit available
Summary
XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote attackers to gain unauthorized access to the X display via a brute force attack.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Exploit-Db
description | XFree86 X11R6 3.3 XDM Session Cookie Guessing Vulnerability. CVE-2001-1086. Remote exploit for unix platform |
id | EDB-ID:20993 |
last seen | 2016-02-02 |
modified | 2001-06-24 |
published | 2001-06-24 |
reporter | ntf & sky |
source | https://www.exploit-db.com/download/20993/ |
title | XFree86 X11R6 3.3 XDM Session Cookie Guessing Vulnerability |
References
- http://online.securityfocus.com/archive/1/195008
- http://online.securityfocus.com/archive/1/195008
- http://www.securityfocus.com/archive/1/194907
- http://www.securityfocus.com/archive/1/194907
- http://www.securityfocus.com/bid/2985
- http://www.securityfocus.com/bid/2985
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6808
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6808