XScreenSaver Symbolic Link Local Information Disclosure Vulnerability
BID:35574
Info
XScreenSaver Symbolic Link Local Information Disclosure Vulnerability
| Bugtraq ID: | 35574 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 05 2009 12:00AM |
| Updated: | Jul 08 2009 08:46PM |
| Credit: | Nikolaos Rangos |
| Vulnerable: |
Xscreensaver Xscreensaver 5.01 |
| Not Vulnerable: | |
Discussion
XScreenSaver Symbolic Link Local Information Disclosure Vulnerability
XScreenSaver is prone to a local information-disclosure vulnerability.
A local attacker can exploit this issue to obtain sensitive information that may lead to further attacks.
XScreenSaver 5.01 is vulnerable; other versions may also be affected.
XScreenSaver is prone to a local information-disclosure vulnerability.
A local attacker can exploit this issue to obtain sensitive information that may lead to further attacks.
XScreenSaver 5.01 is vulnerable; other versions may also be affected.
Exploit / POC
XScreenSaver Symbolic Link Local Information Disclosure Vulnerability
An attacker uses readily available commands to exploit this issue.
An attacker uses readily available commands to exploit this issue.
Solution / Fix
XScreenSaver Symbolic Link Local Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
XScreenSaver Symbolic Link Local Information Disclosure Vulnerability
References:
References:
- Oops! About xscreensaver 5.01 (Kingcope)
- XScreenSaver Homepage (Jamie Zawinski)
- xscreensaver local arbitrary file disclosure | symlink attack (Nikolaos Rangos)
- xscreensaver: symlink attack enables local information disclosure (Debian)