The Red Hat build script for the GNOME Display Manager (GDM) before 2.16.0-56 on Red Hat Enterprise Linux (RHEL) 5 omits TCP Wrapper support, which might allow remote attackers to bypass intended access restrictions via XDMCP connections, a different vulnerability than CVE-2007-5079.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9586 | vdb entry signature |
http://secunia.com/advisories/36553 | third party advisory vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=239818 | |
http://www.securityfocus.com/bid/36219 | vdb entry |
https://rhn.redhat.com/errata/RHSA-2009-1364.html | vendor advisory |