20010705 Re: xdm cookies fast brute forcemailing list
http://online.securityfocus.com/archive/1/195008 CVE-2001-1086
XFree86 X11R6 3.3 XDM - Session Cookie Guessing
Record summary
CVE-2001-1086 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote attackers to gain unauthorized access to the X display via a brute force attack.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBXFree86 X11R6 3.3 XDM - Session Cookie GuessingExploitDB exploitby ntf & skyNot analyzed1 file
References
520010704 xdm cookies fast brute forcemailing list
http://www.securityfocus.com/archive/1/194907 2985vdb entry
http://www.securityfocus.com/bid/2985 xdm-cookie-brute-force(6808)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/6808 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-1086