PT-2011-5245 · X.Org+3 · Xserver+4
Vladz
·
Publicado
1970-01-01
·
Atualizado
2020-08-24
·
CVE-2011-4028
CVSS v2.0
1.9
Baixa
| Vetor | AV:L/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
xorg-server versions prior to 1.10.4-r1
xserver versions prior to 1.11.2
Description
The issue concerns multiple vulnerabilities in the xorg-server package, which can be exploited locally to compromise the confidentiality of protected information. Specifically, the LockServer function in os/utils.c in X.Org xserver is vulnerable to a symlink attack on a temporary lock file, allowing local users to determine the existence of arbitrary files.
Recommendations
For xorg-server versions prior to 1.10.4-r1, update to version 1.10.4-r1 or later to resolve the issue.
For xserver versions prior to 1.11.2, update to version 1.11.2 or later to resolve the issue.
As a temporary workaround, consider restricting access to the LockServer function to minimize the risk of exploitation.
Correção
Link Following
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Centos
Red Hat
Suse
Xorg-Server
Xserver