PT-2006-5950 · Netbsd+2 · X Display Manager+2

Jeremy C. Reed

·

Published

2006-10-09

·

Updated

2018-10-30

·

CVE-2006-5215

CVSS v2.0

2.6

Low

VectorAV:L/AC:H/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions X Display Manager (xdm) in NetBSD versions prior to 20060212 X.Org versions prior to 20060317 Solaris versions 8 through 10 prior to 20061006
Description The issue allows local users to overwrite arbitrary files or read another user's Xsession errors file via a symlink attack on a /tmp/xses-$USER file. This is a result of a flaw in the Xsession script used by the affected software.
Recommendations For X Display Manager (xdm) in NetBSD versions prior to 20060212, update to a version released after 20060212. For X.Org versions prior to 20060317, update to a version released after 20060317. For Solaris versions 8 through 10 prior to 20061006, update to a version released after 20061006.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-5215

Affected Products

Solaris
X Display Manager
X.Org