CVE-2000-0374
Description
The default kdm configuration in Caldera and Mandrake Linux allows XDMCP connections from any host, enabling remote attackers to obtain sensitive information or bypass access controls.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The default kdm configuration in Caldera and Mandrake Linux allows XDMCP connections from any host, enabling remote attackers to obtain sensitive information or bypass access controls.
Vulnerability
The default configuration of the K Display Manager (kdm) in Caldera and Mandrake Linux, and potentially other distributions, accepts X Display Manager Control Protocol (XDMCP) connections from any host without restriction. This is a configuration issue present in the default setup of kdm, leaving the service exposed to network-wide access.
Exploitation
An attacker needs only network access to the target system's XDMCP service (typically on port 177). No authentication is required; the attacker can initiate an XDMCP connection from any remote machine, sending a query or request to the kdm server.
Impact
A successful XDMCP connection can allow the attacker to obtain sensitive information, such as the list of available display managers or system details, or to bypass additional access restrictions that the administrator might have intended. The exact impact depends on the environment, but it fundamentally leaks information and weakens the access control boundary.
Mitigation
No fix is explicitly described in the available references. As a general best practice, administrators should configure kdm to restrict XDMCP connections to trusted hosts only, or disable XDMCP entirely if not needed. Given the age of this vulnerability (1999), it is likely that modern distributions no longer ship with this dangerous default.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.