gnuserv before 3.12, as shipped with XEmacs, does not properly check the specified length of an X Windows MIT-MAGIC-COOKIE cookie, which allows remote attackers to execute arbitrary commands via a buffer overflow, or brute force authentication by using a short cookie length.
References
Configurations
Information
Published : 2001-05-03 04:00
Updated : 2017-10-10 01:29
NVD link : CVE-2001-0191
Mitre link : CVE-2001-0191
JSON object : View
Products Affected
andy_norman
- gnuserv
CWE
