X.Org X Window Server Local Privilege Escalation Vulnerability
BID:17169
Info
X.Org X Window Server Local Privilege Escalation Vulnerability
| Bugtraq ID: | 17169 |
| Class: | Access Validation Error |
| CVE: |
CVE-2006-0745 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 20 2006 12:00AM |
| Updated: | Nov 03 2007 12:06AM |
| Credit: | This issue was discovered through use of the Coverity Prevent code audit tool and was disclosed by the vendor. |
| Vulnerable: |
X.org X11R7 1.0.1 X.org X11R7 1.0 X.org X11R6 6.9 Turbolinux Turbolinux Server 10.0 x86 Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Desktop 10.0 Turbolinux Turbolinux 10 F... TurboLinux Personal TurboLinux Multimedia Turbolinux Home Sun Solaris 10.0_x86 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Personal 10.0 OSS Redhat Fedora Core5 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 |
| Not Vulnerable: |
X.org X11R7 1.0.2 |
Discussion
X.Org X Window Server Local Privilege Escalation Vulnerability
The X.Org X Window server is prone to a privilege-escalation vulnerability.
A local attacker can exploit this issue to load arbitrary modules and execute them or overwrite arbitrary files with superuser privileges. This may facilitate a complete compromise of the affected computer.
The X.Org X Window server is prone to a privilege-escalation vulnerability.
A local attacker can exploit this issue to load arbitrary modules and execute them or overwrite arbitrary files with superuser privileges. This may facilitate a complete compromise of the affected computer.
Exploit / POC
X.Org X Window Server Local Privilege Escalation Vulnerability
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
Solution / Fix
X.Org X Window Server Local Privilege Escalation Vulnerability
Solution:
X.Org has released updates to address this issue.
Please see the referenced vendor advisories for more information.
X.org X11R7 1.0
X.org X11R7 1.0.1
X.org X11R6 6.9
Solution:
X.Org has released updates to address this issue.
Please see the referenced vendor advisories for more information.
X.org X11R7 1.0
-
X.org xorg-server-1.0.1-geteuid.diff
http://xorg.freedesktop.org/releases/X11R7.0/patches/ -
X.org xorg-server-1.0.2.tar.gz
http://xorg.freedesktop.org/releases/individual/xserver/
X.org X11R7 1.0.1
-
X.org xorg-server-1.0.1-geteuid.diff
http://xorg.freedesktop.org/releases/X11R7.0/patches/ -
X.org xorg-server-1.0.2.tar.gz
http://xorg.freedesktop.org/releases/individual/xserver/
X.org X11R6 6.9
-
X.org x11r6.9.0-geteuid.diff
http://xorg.freedesktop.org/releases/X11R6.9.0/patches/ -
X.org xorg-server-1.0.2.tar.gz
http://xorg.freedesktop.org/releases/individual/xserver/
References
X.Org X Window Server Local Privilege Escalation Vulnerability
References:
References: