Vulnerabilities > CVE-2004-1347
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN nessus
Summary
X Display Manager (XDM) on Solaris 8 allows remote attackers to cause a denial of service (XDM crash) via an invalid X Display Manager Control Protocol (XDMCP) request.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 7 |
Nessus
NASL family Solaris Local Security Checks NASL id SOLARIS7_X86_108377.NASL description OpenWindows 3.6.1_x86: Xsun Patch. Date this patch was last updated by Sun : Nov/30/05 last seen 2016-09-26 modified 2011-10-24 plugin id 13243 published 2004-07-12 reporter Tenable source https://www.tenable.com/plugins/index.php?view=single&id=13243 title Solaris 7 (x86) : 108377-41 code #%NASL_MIN_LEVEL 999999 # @DEPRECATED@ # # This script has been deprecated as the associated patch is not # currently a recommended security fix. # # Disabled on 2011/10/24. # # # (C) Tenable Network Security, Inc. # # if ( ! defined_func("bn_random") ) exit(0); include("compat.inc"); if(description) { script_id(13243); script_version("1.23"); script_name(english: "Solaris 7 (x86) : 108377-41"); script_cve_id("CVE-2004-1347", "CVE-2005-3099"); script_set_attribute(attribute: "synopsis", value: "The remote host is missing Sun Security Patch number 108377-41"); script_set_attribute(attribute: "description", value: 'OpenWindows 3.6.1_x86: Xsun Patch. Date this patch was last updated by Sun : Nov/30/05'); script_set_attribute(attribute: "solution", value: "You should install this patch for your system to be up-to-date."); script_set_attribute(attribute: "see_also", value: "http://download.oracle.com/sunalerts/1000872.1.html"); script_set_attribute(attribute: "cvss_vector", value: "CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P"); script_set_attribute(attribute:"plugin_publication_date", value: "2004/07/12"); script_cvs_date("Date: 2018/08/13 14:32:38"); script_set_attribute(attribute:"vuln_publication_date", value: "2004/08/09"); script_end_attributes(); script_summary(english: "Check for patch 108377-41"); script_category(ACT_GATHER_INFO); script_copyright(english:"This script is Copyright (C) 2004-2018 Tenable Network Security, Inc."); family["english"] = "Solaris Local Security Checks"; script_family(english:family["english"]); script_dependencies("ssh_get_info.nasl"); script_require_keys("Host/Solaris/showrev"); exit(0); } # Deprecated. exit(0, "The associated patch is not currently a recommended security fix."); include("solaris.inc"); e += solaris_check_patch(release:"5.7_x86", arch:"i386", patch:"108377-41", obsoleted_by:"", package:"SUNWxwfnt", version:"3.7.2101,REV=0.98.08.26"); e += solaris_check_patch(release:"5.7_x86", arch:"i386", patch:"108377-41", obsoleted_by:"", package:"SUNWxwice", version:"3.7.2100,REV=0.98.08.05"); e += solaris_check_patch(release:"5.7_x86", arch:"i386", patch:"108377-41", obsoleted_by:"", package:"SUNWxwinc", version:"3.7.2100,REV=0.98.08.05"); e += solaris_check_patch(release:"5.7_x86", arch:"i386", patch:"108377-41", obsoleted_by:"", package:"SUNWxwman", version:"3.7.2100,REV=0.98.08.05"); e += solaris_check_patch(release:"5.7_x86", arch:"i386", patch:"108377-41", obsoleted_by:"", package:"SUNWxwopt", version:"3.7.2100,REV=0.98.08.05"); e += solaris_check_patch(release:"5.7_x86", arch:"i386", patch:"108377-41", obsoleted_by:"", package:"SUNWxwplt", version:"3.7.2103,REV=0.98.08.26"); e += solaris_check_patch(release:"5.7_x86", arch:"i386", patch:"108377-41", obsoleted_by:"", package:"SUNWxwpmn", version:"3.7.2100,REV=0.98.08.05"); e += solaris_check_patch(release:"5.7_x86", arch:"i386", patch:"108377-41", obsoleted_by:"", package:"SUNWxwslb", version:"3.7.2100,REV=0.98.08.05"); if ( e < 0 ) { if ( NASL_LEVEL < 3000 ) security_warning(0); else security_warning(port:0, extra:solaris_get_report()); exit(0); } exit(0, "Host is not affected");
NASL family Solaris Local Security Checks NASL id SOLARIS7_108376.NASL description OpenWindows 3.6.1: Xsun Patch. Date this patch was last updated by Sun : Nov/28/05 last seen 2016-09-26 modified 2011-10-24 plugin id 13140 published 2004-07-12 reporter Tenable source https://www.tenable.com/plugins/index.php?view=single&id=13140 title Solaris 7 (sparc) : 108376-46
Oval
accepted | 2005-11-16T08:02:00.000-04:00 | ||||||||
class | vulnerability | ||||||||
contributors |
| ||||||||
description | X Display Manager (XDM) on Solaris 8 allows remote attackers to cause a denial of service (XDM crash) via an invalid X Display Manager Control Protocol (XDMCP) request. | ||||||||
family | unix | ||||||||
id | oval:org.mitre.oval:def:100113 | ||||||||
status | accepted | ||||||||
submitted | 2005-08-16T04:00:00.000-04:00 | ||||||||
title | X Display Manager DoS via Invalid XDMCP Request | ||||||||
version | 36 |
References
- http://secunia.com/advisories/12257/
- http://secunia.com/advisories/12257/
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101549-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101549-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-57619-1&searchclause=security
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-57619-1&searchclause=security
- http://www.kb.cert.org/vuls/id/139504
- http://www.kb.cert.org/vuls/id/139504
- http://www.securityfocus.com/bid/10911
- http://www.securityfocus.com/bid/10911
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16940
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16940
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100113
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100113