xdm open socket allows access
| xdm-socket-gain-access (16264) |
Description:
The XFree86 xdm (X Display Manager) could allow a remote attacker to gain unauthorized access to the system. Even if DisplayManager.requestPort is set to 0, xdm may open random TCP sockets which is caused by a vulnerability in xc/programs/xdm/socket.c. A remote attacker could exploit this vulnerability to gain access to the system.
Platforms Affected:
- Gentoo, Linux
- MandrakeSoft, Mandrake Linux 10.0
- MandrakeSoft, Mandrake Linux 10.0 AMD64
- RedHat, Enterprise Linux 3 ES
- RedHat, Enterprise Linux 3 AS
- RedHat, Enterprise Linux 3 Desktop
- RedHat, Enterprise Linux 3 WS
- XFree86, xdm
Remedy:
Apply the patch to your system, available from the XFree86 Web site. See References.
For Gentoo Linux:
Upgrade to the latest version of XFree86 (4.3.0-r6 or 6.7.0-r1 or later), as listed in GLSA 200407-05. See References.
For Mandrake Linux:
Upgrade to the latest XFree86 package, as listed below.Refer toMandrakeSoft Security Advisory MDKSA-2004:073 : XFree86 for more information.See References.
Mandrake Linux 10.0: 4.3-32.1.100mdk or later
For Red Hat Linux:
Upgrade to the latest XFree86 package, as listed below. Refer to RHSA-2004:478-13 for more information. See References.
Red Hat Enterprise Linux AS (v. 3), ES (v. 3), WS (v. 3), Desktop (v.3): 4.3.0-69 or later
For other distributions:
Contact your vendor for upgrade or patch information.
Consequences:
Gain Access
References:
- CIAC Information Bulletin P-001, Red Hat Updated XFree86 Packages fix Security Issues at http://www.ciac.org/ciac/bulletins/p-001.shtml.
- BID-10423: XFree86 XDM RequestPort Random Open TCP Socket Vulnerability
- CVE-2004-0419: XDM in XFree86 opens a chooserFd TCP socket even when DisplayManager.requestPort is 0, which could allow remote attackers to connect to the port, in violation of the intended restrictions.
- GLSA-200407-05: XFree86, X.org: XDM ignores requestPort setting
- MDKSA-2004:073: Updated XFree86 packages fix issue with xdm opening random sockets
- RHSA-2004-478: XFree86 security update
- SECTRACK ID: 1010306: Xdm May Open Random TCP Sockets
Reported:
May 27, 2004
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
