Record summary

CVE-2001-1086 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.

Description

XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote attackers to gain unauthorized access to the X display via a brute force attack.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBXFree86 X11R6 3.3 XDM - Session Cookie GuessingExploitDB exploitby ntf & skyNot analyzed1 file
ExploitDB

PoC details

References

5