gnuserv before 3.12, as shipped with XEmacs, does not properly check the specified length of an X Windows MIT-MAGIC-COOKIE cookie, which allows remote attackers to execute arbitrary commands via a buffer overflow, or brute force authentication by using a short cookie length.
References
Configurations
Information
Published : 2001-05-02 21:00
Updated : 2017-10-09 18:29
NVD link : CVE-2001-0191
Mitre link : CVE-2001-0191
JSON object : View
CWE
Products Affected
andy_norman
- gnuserv


