CVE-2001-0191

Publication date

2001-05-07 04:00:00

Family

mitre

State

PUBLISHED

Description

gnuserv before 3.12, as shipped with XEmacs, does not properly check the specified length of an X Windows MIT-MAGIC-COOKIE cookie, which allows remote attackers to execute arbitrary commands via a buffer overflow, or brute force authentication by using a short cookie length.