X.Org X 'Server X:1 -sp' Command Information Disclosure Vulnerability
BID:27356
Info
X.Org X 'Server X:1 -sp' Command Information Disclosure Vulnerability
| Bugtraq ID: | 27356 |
| Class: | Unknown |
| CVE: |
CVE-2007-5958 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 17 2008 12:00AM |
| Updated: | Apr 13 2015 09:51PM |
| Credit: | The researcher of this vulnerability wishes to remain anonymous. |
| Vulnerable: |
X.org Xserver 1.3 X.org xorg-server 1.4 X.org xorg-server 1.3.99.2 (RC2) X.org xorg-server 1.2 X.org xorg-server 1.02-r5 X.org xorg-server 1.0.2-r6 X.org X11R7 1.1.1 X.org X11R7 1.0.2 X.org X11R7 1.0.1 X.org X11R7 1.0 X.org X11R7 7.2 X.org X11R7 7.1 X.org X11R7 7.0 X.org X11R6 6.9 X.org X11R6 6.8.2 X.org X11R6 6.8.1 X.org X11R6 6.8 X.org X11R6 6.7 .0 X.org X11R6 5.1 X.org X11R6 4.0 X.org LibXfont 1.3.1 Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 9 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE Linux Desktop 10 SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc Sun Solaris 9_x86 Sun Solaris 9_sparc Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 10_x86 Sun Solaris 10_sparc S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.1 rPath rPath Linux 1 rPath Appliance Platform Linux Service 1 Redhat Fedora 7 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux Virtualization 5 Server Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Enterprise Linux 5 Server Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 OpenBSD OpenBSD 4.3 OpenBSD OpenBSD 4.2 OpenBSD OpenBSD 4.1 NoMachine nx-X11 3.1 -3 NoMachine NX Server 3.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 Linux Terminal Server Project Linux Terminal Server Project 4.2 HP HP-UX B.11.31 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.23 HP HP-UX B.11.11 HP HP-UX B.11.11 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Avaya Interactive Response 3.0 Avaya Interactive Response 2.0 Avaya CMS Server 13.0 Avaya CMS Server 12.0 Avaya CMS Server 14.0 Avaya CMS Server 13.1 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.4.11 Apple Mac OS X 10.5.2 Apple Mac OS X 10.4.11 |
| Not Vulnerable: |
X.org xorg-server 1.4.1 NoMachine nx-X11 3.1 -4 Linux Terminal Server Project Linux Terminal Server Project 5.0 |
Discussion
X.Org X 'Server X:1 -sp' Command Information Disclosure Vulnerability
X.Org X Server is prone to a local information-disclosure vulnerability.
Attackers can exploit this issue to gain access to sensitive information that may lead to further attacks.
NOTE: This vulnerability was previously covered in BID 27336 (X.Org X Server Multiple Local Privilege Escalation and Information Disclosure Vulnerabilities), but has been given its own record to better document the issue.
X.Org X Server is prone to a local information-disclosure vulnerability.
Attackers can exploit this issue to gain access to sensitive information that may lead to further attacks.
NOTE: This vulnerability was previously covered in BID 27336 (X.Org X Server Multiple Local Privilege Escalation and Information Disclosure Vulnerabilities), but has been given its own record to better document the issue.
Exploit / POC
X.Org X 'Server X:1 -sp' Command Information Disclosure Vulnerability
Attackers can exploit this issue by using the 'X :1 -sp <file>' command.
Attackers can exploit this issue by using the 'X :1 -sp <file>' command.
Solution / Fix
X.Org X 'Server X:1 -sp' Command Information Disclosure Vulnerability
Solution:
The vendor has released an update and an advisory. Please see the references for more information.
OpenBSD OpenBSD 4.3
Sun Solaris 8_sparc
OpenBSD OpenBSD 4.2
X.org xorg-server 1.2
X.org xorg-server 1.4
OpenBSD OpenBSD 4.1
Sun Solaris 10_x86
X.org LibXfont 1.3.1
Apple Mac OS X 10.4.11
Apple Mac OS X Server 10.4.11
Apple Mac OS X 10.5.2
Solution:
The vendor has released an update and an advisory. Please see the references for more information.
OpenBSD OpenBSD 4.3
-
OpenBSD 003_xorg.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.3/common/003_xorg.patch
Sun Solaris 8_sparc
OpenBSD OpenBSD 4.2
-
OpenBSD 006_xorg.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.2/common/006_xorg.patch
X.org xorg-server 1.2
-
X.org xorg-xserver-1.2-multiple-overflows.diff
ftp://ftp.freedesktop.org/pub/xorg/X11R7.2/patches/xorg-xserver-1.2-mu ltiple-overflows.diff
X.org xorg-server 1.4
-
X.org xorg-xserver-1.4-multiple-overflows.diff
ftp://ftp.freedesktop.org/pub/xorg/X11R7.3/patches/xorg-xserver-1.4-mu ltiple-overflows.diff
OpenBSD OpenBSD 4.1
-
OpenBSD 012_xorg.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.1/common/012_xorg.patch
Sun Solaris 10_x86
-
Sun 119060-37
Xsun
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -119060-37-1 -
Sun 125720-17
Xorg
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -125720-17-1
X.org LibXfont 1.3.1
-
X.org xorg-libXfont-1.3.1-pcf-parser.diff
ftp://ftp.freedesktop.org/pub/xorg/X11R7.3/patches/xorg-libXfont-1.3.1 -pcf-parser.diff
Apple Mac OS X 10.4.11
-
Apple SecUpd2008-002PPC.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpd2008-002PPC.dmg -
Apple SecUpd2008-002Univ.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpd2008-002Univ.dmg
Apple Mac OS X Server 10.4.11
-
Apple SecUpdSrvr2008-002PPC.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpdSrvr2008-002PPC.dmg -
Apple SecUpdSrvr2008-002Univ.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpdSrvr2008-002Univ.dmg
Apple Mac OS X 10.5.2
References
X.Org X 'Server X:1 -sp' Command Information Disclosure Vulnerability
References:
References:
- OpenBSD 4.1 Errata Page (OpenBSD)
- OpenBSD 4.2 Errata Page (OpenBSD)
- OpenBSD 4.3 Errata Page (OpenBSD)
- Second Maintenance Release of the NX 3.1.0 Node Packages (NoMachine)
- X.Org Homepage (X.Org)
- ASA-2008-084 Security Vulnerability in the Solaris X Server May Lead to Unauthor (Avaya)
- HPSBUX02381 SSRT080083 rev.1 - HP-UX Running Xserver, Remote Execution of Arbitr (HP)
- HPSBUX02381 SSRT080083 rev.2 - HP-UX Running Xserver, Remote Execution of Arbitr (HP)
- RHSA-2008:0029-9 XFree86 security update (Red Hat)
- RHSA-2008:0030-7 xorg-x11 security update (Red Hat)
- RHSA-2008:0031-8 xorg-x11-server security update (Red Hat)
- Solution 230901 : Security Vulnerability in the Solaris X Server May Lead to (Sun)
- Sun Alert ID: 103205 Security Vulnerability in the Solaris X Server May Lead to (Sun)
- X.Org security advisory, January 17th, 2008 (X.Org)