VYPR
Unrated severityNVD Advisory· Published Aug 22, 1999· Updated Apr 16, 2026

CVE-2000-0374

CVE-2000-0374

Description

The default kdm configuration in Caldera and Mandrake Linux allows XDMCP connections from any host, enabling remote attackers to obtain sensitive information or bypass access controls.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The default kdm configuration in Caldera and Mandrake Linux allows XDMCP connections from any host, enabling remote attackers to obtain sensitive information or bypass access controls.

Vulnerability

The default configuration of the K Display Manager (kdm) in Caldera and Mandrake Linux, and potentially other distributions, accepts X Display Manager Control Protocol (XDMCP) connections from any host without restriction. This is a configuration issue present in the default setup of kdm, leaving the service exposed to network-wide access.

Exploitation

An attacker needs only network access to the target system's XDMCP service (typically on port 177). No authentication is required; the attacker can initiate an XDMCP connection from any remote machine, sending a query or request to the kdm server.

Impact

A successful XDMCP connection can allow the attacker to obtain sensitive information, such as the list of available display managers or system details, or to bypass additional access restrictions that the administrator might have intended. The exact impact depends on the environment, but it fundamentally leaks information and weakens the access control boundary.

Mitigation

No fix is explicitly described in the available references. As a general best practice, administrators should configure kdm to restrict XDMCP connections to trusted hosts only, or disable XDMCP entirely if not needed. Given the age of this vulnerability (1999), it is likely that modern distributions no longer ship with this dangerous default.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3
  • Caldera/Openlinux2 versions
    cpe:2.3:o:caldera:openlinux:2.2:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:caldera:openlinux:2.2:*:*:*:*:*:*:*
    • cpe:2.3:o:caldera:openlinux:2.3:*:*:*:*:*:*:*
  • KDE/KDMllm-fuzzy

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.