PT-2006-5950 · Netbsd+2 · X Display Manager+2
Jeremy C. Reed
·
Published
2006-10-09
·
Updated
2018-10-30
·
CVE-2006-5215
CVSS v2.0
2.6
Low
| Vector | AV:L/AC:H/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
X Display Manager (xdm) in NetBSD versions prior to 20060212
X.Org versions prior to 20060317
Solaris versions 8 through 10 prior to 20061006
Description
The issue allows local users to overwrite arbitrary files or read another user's Xsession errors file via a symlink attack on a /tmp/xses-$USER file. This is a result of a flaw in the Xsession script used by the affected software.
Recommendations
For X Display Manager (xdm) in NetBSD versions prior to 20060212, update to a version released after 20060212.
For X.Org versions prior to 20060317, update to a version released after 20060317.
For Solaris versions 8 through 10 prior to 20061006, update to a version released after 20061006.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Solaris
X Display Manager
X.Org