Conectiva Linux Security Announcement - gdm | Linux Today

Conectiva Linux Security Announcement – gdm

Written By
Web Webster
Web Webster
Jun 7, 2000

[ Thanks to Sergio
Bruder
for this announcement. ]

CONECTIVA LINUX SECURITY ANNOUNCEMENT

PACKAGE: gdm

SUMMARY : Remote buffer overflow
DATE : 2000-JUN-06
AFFECTED CONECTIVA VERSIONS : 4.1, 4.2 and 5.0

DESCRIPTION
The gdm program is on of the graphical login choices available
for Conectiva Linux users. A serious vulnerability has been found
in this program during the XDMCP protocol processing that could
lead to remote root compromise.

In order to exploit this vulnerability, the XDMCP option has to be
explicitly enabled in /etc/X11/gdm/gdm.conf. All Conectiva Linux
versions ship with this options DISABLED by default.

SOLUTION
If you need to use XDMCP, then you MUST upgrade the gdm program to
the latest release following the links below. If XDMCP is disabled
in /etc/X11/gdm/gdm.conf, then this vulnerability cannot be
exploited.

DIRECT DOWNLOAD LINKS TO UPDATED PACKAGES:
ftp://ftp.conectiva.com.br/pub/conectiva/atualizacoes/4.1/i386/gdm-2.0beta4-2cl.i386.rpm

ftp://ftp.conectiva.com.br/pub/conectiva/atualizacoes/4.2/i386/gdm-2.0beta4-2cl.i386.rpm

ftp://ftp.conectiva.com.br/pub/conectiva/atualizacoes/5.0/i386/gdm-2.0beta4-2cl.i386.rpm

SOURCE RPM PACKAGES ARE ALSO AVAILABLE:
ftp://ftp.conectiva.com.br/pub/conectiva/atualizacoes/4.1/SRPMS/gdm-2.0beta4-2cl.src.rpm

ftp://ftp.conectiva.com.br/pub/conectiva/atualizacoes/4.2/SRPMS/gdm-2.0beta4-2cl.src.rpm

ftp://ftp.conectiva.com.br/pub/conectiva/atualizacoes/5.0/SRPMS/gdm-2.0beta4-2cl.src.rpm

All packages are signed with Conectiva’s PGP key. The key can be
obtained at http://www.conectiva.com.br/conectiva/contato.html

Information on how to install and/or update packages, and mirror
sites, can be found at http://www.conectiva.com.br/atualizacoes


subscribe: atualizacoes-anuncio-subscribe@bazar.conectiva.com.br

unsubscribe: atualizacoes-anuncio-unsubscribe@bazar.conectiva.com.br

Web Webster

Web Webster

Web Webster has more than 20 years of writing and editorial experience in the tech sector. He’s written and edited news, demand generation, user-focused, and thought leadership content for business software solutions, consumer tech, and Linux Today, he edits and writes for a portfolio of tech industry news and analysis websites including webopedia.com, and DatabaseJournal.com.

Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.