X.Org XDM XSession Script Race Condition Vulnerability
BID:20400
Info
X.Org XDM XSession Script Race Condition Vulnerability
| Bugtraq ID: | 20400 |
| Class: | Race Condition Error |
| CVE: |
CVE-2006-5214 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 06 2006 12:00AM |
| Updated: | Aug 10 2007 05:34PM |
| Credit: | Steven M. Bellovin is credited with the discovery of this vulnerability. |
| Vulnerable: |
X.org X11R7 7.1 Ubuntu Ubuntu Linux 5.10 sparc Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Sun Solaris 9_x86 Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 10_x86 Sun Solaris 10.0_x86 Sun Solaris 10.0 Sun Solaris 10 Redhat Fedora Core6 NetBSD NetBSD Current Avaya CMS Server 13.0 Avaya CMS Server 12.0 Avaya CMS Server 11.0 Avaya CMS Server 10.0 Avaya CMS Server 9.0 Avaya CMS Server 13.1 |
| Not Vulnerable: | |
Discussion
X.Org XDM XSession Script Race Condition Vulnerability
The X.org XDM XSession script is prone to a race-condition vulnerability.
Local unprivileged attackers can exploit this issue to gain access to the primary or alternate 'xdm' error log files. Successful exploits will allow attackers to obtain sensitive information.
The X.org XDM XSession script is prone to a race-condition vulnerability.
Local unprivileged attackers can exploit this issue to gain access to the primary or alternate 'xdm' error log files. Successful exploits will allow attackers to obtain sensitive information.
Exploit / POC
X.Org XDM XSession Script Race Condition Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
X.Org XDM XSession Script Race Condition Vulnerability
Solution:
The vendor has committed a change to CVS that addresses this issue. Please see the references for more information.
Sun Solaris 10.0
Ubuntu Ubuntu Linux 6.06 LTS amd64
Sun Solaris 9
Sun Solaris 9_x86
Sun Solaris 10.0_x86
Ubuntu Ubuntu Linux 6.06 LTS sparc
Sun Solaris 8_x86
Ubuntu Ubuntu Linux 6.06 LTS powerpc
Sun Solaris 8_sparc
Ubuntu Ubuntu Linux 6.06 LTS i386
Ubuntu Ubuntu Linux 5.10 powerpc
Ubuntu Ubuntu Linux 5.10 i386
Ubuntu Ubuntu Linux 5.10 amd64
Solution:
The vendor has committed a change to CVS that addresses this issue. Please see the references for more information.
Sun Solaris 10.0
-
Sun 124457-01
http://sunsolve.sun.com/patches
Ubuntu Ubuntu Linux 6.06 LTS amd64
-
Ubuntu xinit_1.0.1-0ubuntu3.1_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/x/xinit/xinit_1.0.1-0ubunt u3.1_amd64.deb -
Ubuntu xinit_1.0.1-0ubuntu3.1_i386.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/x/xinit/xinit_1.0.1-0ubunt u3.1_i386.deb
Sun Solaris 9
-
Sun 124830-01
http://sunsolve.sun.com/
Sun Solaris 9_x86
-
Sun 124831-01
http://sunsolve.sun.com/
Sun Solaris 10.0_x86
-
Sun 124458-01
http://sunsolve.sun.com/patches
Ubuntu Ubuntu Linux 6.06 LTS sparc
-
Ubuntu xinit_1.0.1-0ubuntu3.1_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/x/xinit/xinit_1.0.1-0ubunt u3.1_sparc.deb
Sun Solaris 8_x86
-
Sun 111845-04
http://sunsolve.sun.com/
Ubuntu Ubuntu Linux 6.06 LTS powerpc
-
Ubuntu xinit_1.0.1-0ubuntu3.1_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/x/xinit/xinit_1.0.1-0ubunt u3.1_powerpc.deb
Sun Solaris 8_sparc
-
Sun 111844-04
http://sunsolve.sun.com/
Ubuntu Ubuntu Linux 6.06 LTS i386
-
Ubuntu xinit_1.0.1-0ubuntu3.1_i386.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/x/xinit/xinit_1.0.1-0ubunt u3.1_i386.deb
Ubuntu Ubuntu Linux 5.10 powerpc
-
Ubuntu xinit_1.0+0.99.1-4ubuntu0.1_powerpc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/x/xinit/xinit_1.0+0.99.1-4 ubuntu0.1_powerpc.deb -
Ubuntu xinit_1.0.1-0ubuntu3.1_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/x/xinit/xinit_1.0.1-0ubunt u3.1_amd64.deb
Ubuntu Ubuntu Linux 5.10 i386
-
Ubuntu xinit_1.0+0.99.1-4ubuntu0.1_i386.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/x/xinit/xinit_1.0+0.99.1-4 ubuntu0.1_i386.deb
Ubuntu Ubuntu Linux 5.10 amd64
-
Ubuntu xinit_1.0+0.99.1-4ubuntu0.1_amd64.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/x/xinit/xinit_1.0+0.99.1-4 ubuntu0.1_amd64.deb
References
X.Org XDM XSession Script Race Condition Vulnerability
References:
References:
- NetBSD Problem Report #32804 (NetBSD)
- race condition on $HOME/.xsession-errors being readable (freedesktop.org)
- X.org CVS Commit Thread (freedesktop.org)
- X.Org Home Page (X.Org)
- Avaya Security Advisory ASA-2006-250 (Avaya Inc.)
- Sun Alert ID: 102652 - Security Vulnerability in X Display Manager (xdm(1)) Xses (Sun)