X.Org X Window Server LibX11 Xinput File Descriptor Leak Vulnerability
BID:20845
Info
X.Org X Window Server LibX11 Xinput File Descriptor Leak Vulnerability
| Bugtraq ID: | 20845 |
| Class: | Design Error |
| CVE: |
CVE-2006-5397 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 01 2006 12:00AM |
| Updated: | Jan 16 2007 06:20PM |
| Credit: | Kees Cook is credited with the discovery of this vulnerability. |
| Vulnerable: |
X.org X11R7 7.0 X.org libx11 1.0.3 X.org libx11 1.0.2 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 |
| Not Vulnerable: | |
Discussion
X.Org X Window Server LibX11 Xinput File Descriptor Leak Vulnerability
X.Org X Window Server libX11 library 'Xinput' module is prone to a file-descriptor leak due to a design error.
The vulnerability arises because the application fails to close a file descriptor after file operations. An attacker can exploit this issue to open files with elevated privileges.
Versions 1.0.2 and 1.0.3 of libX11 are reported affected; other versions may be affected as well.
X.Org X Window Server libX11 library 'Xinput' module is prone to a file-descriptor leak due to a design error.
The vulnerability arises because the application fails to close a file descriptor after file operations. An attacker can exploit this issue to open files with elevated privileges.
Versions 1.0.2 and 1.0.3 of libX11 are reported affected; other versions may be affected as well.
Exploit / POC
Solution / Fix
X.Org X Window Server LibX11 Xinput File Descriptor Leak Vulnerability
Solution:
Reportedly, this issue has been addressed in the freedesktop.org GIT repository. Symantec was unable to confirm this information.
Please see the referenced vendor advisories for more information.
X.org libx11 1.0.3
Solution:
Reportedly, this issue has been addressed in the freedesktop.org GIT repository. Symantec was unable to confirm this information.
Please see the referenced vendor advisories for more information.
X.org libx11 1.0.3
-
Mandriva lib64x11_6-1.0.3-2.1mdv2007.0.x86_64.rpm
Mandriva Linux 2007.0:
http://www.mandriva.com/en/download -
Mandriva lib64x11_6-devel-1.0.3-2.1mdv2007.0.x86_64.rpm
Mandriva Linux 2007.0:
http://www.mandriva.com/en/download -
Mandriva lib64x11_6-static-devel-1.0.3-2.1mdv2007.0.x86_64.rpm
Mandriva Linux 2007.0:
http://www.mandriva.com/en/download -
Mandriva libx11-1.0.3-2.1mdv2007.0.src.rpm
Mandriva Linux 2007.0:
http://www.mandriva.com/en/download -
Mandriva libx11-common-1.0.3-2.1mdv2007.0.i586.rpm
Mandriva Linux 2007.0:
http://www.mandriva.com/en/download -
Mandriva libx11-common-1.0.3-2.1mdv2007.0.x86_64.rpm
Mandriva Linux 2007.0:
http://www.mandriva.com/en/download -
Mandriva libx11_6-1.0.3-2.1mdv2007.0.i586.rpm
Mandriva Linux 2007.0:
http://www.mandriva.com/en/download -
Mandriva libx11_6-devel-1.0.3-2.1mdv2007.0.i586.rpm
Mandriva Linux 2007.0:
http://www.mandriva.com/en/download -
Mandriva libx11_6-static-devel-1.0.3-2.1mdv2007.0.i586.rpm
Mandriva Linux 2007.0:
http://www.mandriva.com/en/download
References
X.Org X Window Server LibX11 Xinput File Descriptor Leak Vulnerability
References:
References:
- FreeDesktop Bugzilla Bug 8699 (FreeDesktop)
- X.org Home Page (X.org)