PT-2006-1063 · X.Org+2 · Libx11+8

Dirk Mueller

+1

·

Publicado

2006-08-28

·

Atualizado

2011-03-08

·

CVE-2006-4447

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: xdm versions prior to 1.0.4-r1
Description: The issue concerns multiple vulnerabilities in the xdm package, which can be exploited locally to compromise the confidentiality, integrity, and availability of protected information. Specifically, the X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans, and xterm, do not check the return values for setuid and seteuid calls when attempting to drop privileges. This might allow local users to gain privileges by causing those calls to fail, such as by exceeding a ulimit.
Recommendations: For xdm versions prior to 1.0.4-r1, update to version 1.0.4-r1 or later to resolve the issue. As a temporary workaround, consider restricting access to the xdm package to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-09522
CVE-2006-4447
DSA-1193-1

Produtos afetados

Debian
Xfree86
Libx11
Xdm
Xf86Dga
Xinit
Xload
Xterm
Xtrans