Security Fix 008 for 3.5-stable: xdm

008: SECURITY FIX: May 26, 2004
With the introduction of IPv6 code in xdm(1), one test on the 'requestPort' resource was deleted by accident. This makes xdm create the chooser socket even if xdmcp is disabled in xdm-config, by setting requestPort to 0. See XFree86 bugzilla for details.
A source code patch exists which remedies this problem.

Update: thanks to Brad Smith for pointing out that this issue does not affect 3.4.

  1. By Brad ( brad at comstyle dot com on

    XFree86 (4.3) that comes with OpenBSD 3.4 is not affected by this issue since the IPv6 integration happened between (XFree86) 4.3 and 4.4.

