PT-2020-7175 · Debian · X11-Common

Kurt Seifried

·

Published

2020-02-21

·

Updated

2021-02-25

·

CVE-2012-1093

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Debian x11-common versions prior to 1:7.6+12
Description The init script in the Debian x11-common package is vulnerable to a symlink attack, which can lead to a privilege escalation during package installation.
Recommendations For versions prior to 1:7.6+12, update to version 1:7.6+12 or later to resolve the issue. As a temporary workaround, consider restricting package installation privileges to minimize the risk of exploitation.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-1093

Affected Products

X11-Common