CVE-2004-0419

6 documents6 sources
Severity
7.5HIGH
EPSS
2.8%
top 13.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 18
Latest updateApr 29

Description

XDM in XFree86 opens a chooserFd TCP socket even when DisplayManager.requestPort is 0, which could allow remote attackers to connect to the port, in violation of the intended restrictions.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

NVDx.org/x11r66.7.0
NVDgentoo/linux1.4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-xcpv-777v-f4v3: XDM in XFree86 opens a chooserFd TCP socket even when DisplayManager2022-04-29
CVEList
CVE-2004-0419: XDM in XFree86 opens a chooserFd TCP socket even when DisplayManager2004-06-03

📋Vendor Advisories

2
Red Hat
security flaw2004-05-19
Debian
CVE-2004-0419: xdm - XDM in XFree86 opens a chooserFd TCP socket even when DisplayManager.requestPort...2004

💬Community

1
Bugzilla
CVE-2004-0419 security flaw2018-08-16
CVE-2004-0419 (HIGH CVSS 7.5) | XDM in XFree86 opens a chooserFd TC | cvebase.io