CVE-2000-0491

GNOME gdm - Remote Code Execution via XDMCP FORWARD_QUERY Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2000-0491. PoCs published by AbraxaS, Chris Evans.

AI-analyzed exploit summary This exploit targets a buffer overflow in GNOME Display Manager (gdm) via maliciously crafted XDMCP messages. It sends a FORWARD_QUERY request with a large payload containing NOPs and shellcode to execute a bind shell on port 3879.

Description

Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of service via a long FORWARD_QUERY request.

Exploits (2)

exploitdb WORKING POC VERIFIED
by AbraxaS · cremotelinux
https://www.exploit-db.com/exploits/19948

This exploit targets a buffer overflow in GNOME Display Manager (gdm) via maliciously crafted XDMCP messages. It sends a FORWARD_QUERY request with a large payload containing NOPs and shellcode to execute a bind shell on port 3879.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: GNOME Display Manager (gdm) 2.0beta1-4 and 2.0beta2
No auth needed
Prerequisites: XDMCP enabled in gdm configuration · Network access to UDP port 177
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Chris Evans · cremotelinux
https://www.exploit-db.com/exploits/19947

This exploit targets a buffer overflow in the XDMCP handling code of 'gdm' (GNOME Display Manager) by sending a maliciously crafted FORWARD_QUERY request. The overflow occurs due to improper handling of the remote display field, allowing arbitrary command execution as root.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: gdm (GNOME Display Manager) versions shipped with RedHat 6.0-6.2, Helix GNOME, and source builds configured to accept XDMCP requests
No auth needed
Prerequisites: XDMCP must be enabled in gdm configuration (e.g., /etc/X11/gdm/gdm.conf with 'Enable' set to 1)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2000-06/0025.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1279
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1370
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1233
Patch, Vendor Advisory vendor-advisory x_refsource_caldera
ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-013.0.txt
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2000-05/0241.html

Scores

EPSS 0.1778
EPSS Percentile 96.8%

Details

Status published
Products (4)
caldera/openlinux
gnome/gdm 1.0
suse/suse_linux 6.2
suse/suse_linux 6.4
Published May 24, 2000
Tracked Since Feb 18, 2026