Vulnerability Name:

CVE-2002-1510 (CCN-11389)

Assigned:2001-12-12
Published:2001-12-12
Updated:2008-09-05
Summary:xdm, with the authComplain variable set to false, allows arbitrary attackers to connect to the X server if the xdm auth directory does not exist.
CVSS v3 Severity:10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: OpenBSD CVS Commits Mailing List, Mon Oct 01 2001 - 16:44:44 CDT
CVS: cvs.openbsd.org: XF4

Source: MITRE
Type: CNA
CVE-2002-1510

Source: CCN
Type: Conectiva Linux Announcement CLSA-2002:533
XFree86

Source: CONECTIVA
Type: UNKNOWN
CLA-2002:533

Source: CCN
Type: RHSA-2003-064
Updated XFree86 4.1.0 packages are available

Source: CCN
Type: RHSA-2003-065
XFree86 security update

Source: CCN
Type: Sun Alert ID: 55602
Sun Linux 5.0 Security Vulnerabilities in XFree86 Packages

Source: SUNALERT
Type: UNKNOWN
55602

Source: MISC
Type: Vendor Advisory
http://wuarchive.wustl.edu/mirrors/NetBSD/NetBSD-current/xsrc/xfree/xc/programs/Xserver/hw/xfree86/CHANGELOG

Source: XF
Type: Vendor Advisory
xfree86-xdm-unauth-access(11389)

Source: REDHAT
Type: UNKNOWN
RHSA-2003:064

Source: REDHAT
Type: UNKNOWN
RHSA-2003:065

Source: CCN
Type: XFree86 Web site
XFree86(TM): Home Page

Source: XF
Type: UNKNOWN
xfree86-xdm-unauth-access(11389)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:xfree86_project:x11r6:*:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:conectiva:linux:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:7.1:*:*:*:*:*:*:*
  • OR cpe:/o:conectiva:linux:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:7.2:*:*:*:*:*:*:*
  • OR cpe:/a:sun:linux:5.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:2.1:*:as:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:2.1:*:es:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:2.1:*:ws:*:*:*:*:*
  • OR cpe:/o:redhat:linux_advanced_workstation:2.1:*:itanium:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    xfree86_project x11r6 *
    conectiva linux 6.0
    redhat linux 7.1
    conectiva linux 7.0
    redhat linux 7.2
    sun linux 5.0
    redhat enterprise linux 2.1
    redhat enterprise linux 2.1
    redhat enterprise linux 2.1
    redhat linux advanced workstation 2.1