Vulnerability record · CVE-2001-0191 · published 3 May 2001
CVE-2001-0191: Andynorman gnuserv classic buffer overflow vulnerability
Andynorman · Gnuserv
gnuserv before 3.12, as shipped with XEmacs, does not properly check the specified length of an X Windows MIT-MAGIC-COOKIE cookie, which allows remote attackers to execute arbitrary commands via a buffer overflow, or brute force authentication by using a short cookie length.
Description
gnuserv before 3.12, as shipped with XEmacs, does not properly check the specified length of an X Windows MIT-MAGIC-COOKIE cookie, which allows remote attackers to execute arbitrary commands via a buffer overflow, or brute force authentication by using a short cookie length.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://archives.neohapsis.com/archives/bugtraq/2001-02/0030.html | Broken LinkPatchVendor Advisory |
| http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-019.php3 | Broken LinkPatch |
| http://www.redhat.com/support/errata/RHSA-2001-010.html | Broken LinkPatch |
| http://www.redhat.com/support/errata/RHSA-2001-011.html | Broken LinkPatch |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/6056 | Third Party AdvisoryVDB Entry |
| http://archives.neohapsis.com/archives/bugtraq/2001-02/0030.html | Broken LinkPatchVendor Advisory |
| http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-019.php3 | Broken LinkPatch |
| http://www.redhat.com/support/errata/RHSA-2001-010.html | Broken LinkPatch |
| http://www.redhat.com/support/errata/RHSA-2001-011.html | Broken LinkPatch |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/6056 | Third Party AdvisoryVDB Entry |
Track CVE-2001-0191 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2001-0191), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.