Overview
There is a vulnerability in the way Sun Solaris handles invalid X Display Manager Control Protocol (XDMCP) requests. Exploitation of this vulnerability could allow an attacker to cause the X Display Manager (XDM) to crash.
Description
| The X Display Manager (xdm(1)) is responsible for managing collections of X displays from local or remote servers using the X Display Manager Control Protocol (XDMCP). The Sun Solaris X Display Manager contains a denial-of-service vulnerability that could be triggered by an invalid XDMCP packet. | 
Impact
| A remote attacker with the ability to send XDMCP packets to a vulnerable system could cause the X Display Manager to crash. | 
Solution
| Apply patch Sun has issued an advisory which addresses this issue. For more information on patches available for your system, please refer to Sun Security Alert 57619. | 
| 
 | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental | 
References
Acknowledgements
This vulnerability was reported by Sun Microsystems.
This document was written by Damon Morda.
Other Information
| CVE IDs: | None | 
| Severity Metric: | 4.30 | 
| Date Public: | 2004-08-09 | 
| Date First Published: | 2004-08-11 | 
| Date Last Updated: | 2004-08-11 18:39 UTC | 
| Document Revision: | 16 |