X.Org xrdb Remote Arbitrary Shell Command Injection Vulnerability
BID:47189
Info
X.Org xrdb Remote Arbitrary Shell Command Injection Vulnerability
| Bugtraq ID: | 47189 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-0465 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 06 2011 12:00AM |
| Updated: | Apr 13 2015 10:19PM |
| Credit: | Sebastian Krahmer from SUSE security team |
| Vulnerable: |
Xerox FreeFlow Print Server (FFPS) 93.E0.21C Xerox FreeFlow Print Server (FFPS) 91.D2.32 Xerox FreeFlow Print Server (FFPS) 82.D1.44 Xerox FreeFlow Print Server (FFPS) 81.D0.73 Xerox FreeFlow Print Server (FFPS) 73.D2.33 Xerox FreeFlow Print Server (FFPS) 73.C5.11 X.org xrdb 1.0.8 Ubuntu Ubuntu Linux 9.10 sparc Ubuntu Ubuntu Linux 9.10 powerpc Ubuntu Ubuntu Linux 9.10 lpia Ubuntu Ubuntu Linux 9.10 i386 Ubuntu Ubuntu Linux 9.10 ARM Ubuntu Ubuntu Linux 9.10 amd64 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 11 SP1 SuSE SUSE Linux Enterprise Server 10 SP4 SuSE SUSE Linux Enterprise Server 10 SP3 SuSE SUSE Linux Enterprise SDK 10 SP4 SuSE SUSE Linux Enterprise SDK 10 SP3 SuSE Suse Linux Enterprise Desktop 11 SP1 SuSE Suse Linux Enterprise Desktop 10 SP4 SuSE Suse Linux Enterprise Desktop 10 SP3 Sun Solaris 9 Sun Solaris 10 Slackware Linux x86_64 -current Slackware Linux 13.1 x86_64 Slackware Linux 13.1 Slackware Linux 13.0 x86_64 Slackware Linux 13.0 Slackware Linux 12.2 Slackware Linux 12.1 Slackware Linux 12.0 Slackware Linux -current S.u.S.E. openSUSE 11.4 S.u.S.E. openSUSE 11.3 S.u.S.E. openSUSE 11.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node Optional 6 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux Desktop 6 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux Desktop version 4 Redhat Enterprise Linux 5 Server Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 Mandriva Linux Mandrake 2010.0 x86_64 Mandriva Linux Mandrake 2010.0 Mandriva Linux Mandrake 2009.0 x86_64 Mandriva Linux Mandrake 2009.0 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 Gentoo Linux Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 Avaya Voice Portal 4.1 SP2 Avaya Voice Portal 4.1 SP1 Avaya Voice Portal 4.1 Avaya Voice Portal 4.0 Avaya Proactive Contact 4.1.2 Avaya Proactive Contact 4.1.1 Avaya Proactive Contact 4.2.1 Avaya Proactive Contact 4.2 Avaya Proactive Contact 4.1 Avaya Proactive Contact 4.0.1 Avaya Proactive Contact 4.0 Avaya Messaging Storage Server MSS 5.1 Avaya Messaging Storage Server MSS 4.1 Avaya Messaging Storage Server 5.2.8 Avaya Messaging Storage Server 5.2.2 Avaya Messaging Storage Server 5.2 SP3 Avaya Messaging Storage Server 5.2 SP2 Avaya Messaging Storage Server 5.2 SP1 Avaya Messaging Storage Server 5.2 Avaya Messaging Storage Server 5.1 SP2 Avaya Messaging Storage Server 5.1 SP1 Avaya Messaging Storage Server 5.1 Avaya Messaging Storage Server 5.0 Avaya Messaging Storage Server 4.0 Avaya Message Networking 5.2.1 Avaya Message Networking MN 3.1 Avaya Message Networking 5.2.2 Avaya Message Networking 5.2 SP1 Avaya Message Networking 5.2 Avaya Message Networking 3.1 Avaya IQ 4.1 Avaya IQ 5.2 Avaya IQ 5.1 Avaya IQ 5 Avaya IQ 4.2 Avaya IQ 4.0 Avaya Communication Server 1000M Signaling Server 7.5 Avaya Communication Server 1000M Signaling Server 7.0 Avaya Communication Server 1000M Signaling Server 6.0 Avaya Communication Server 1000M 7.5 Avaya Communication Server 1000M 7.0 Avaya Communication Server 1000M 6.0 Avaya Communication Server 1000E Signaling Server 7.5 Avaya Communication Server 1000E Signaling Server 7.0 Avaya Communication Server 1000E Signaling Server 6.0 Avaya Communication Server 1000E 7.5 Avaya Communication Server 1000E 7.0 Avaya Communication Server 1000E 6.0 Avaya Aura System Platform SP1.1 Avaya Aura System Platform 6.0 SP3 Avaya Aura System Platform 6.0 SP2 Avaya Aura System Platform 6.0 Avaya Aura System Platform 1.0 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 Attachmate Reflection X 2011 Attachmate Reflection for UNIX and OpenVMS 14.0.5 Attachmate Reflection for IBM 14.0.5 Attachmate Reflection for IBM 14 Attachmate Reflection for HP 14.0.5 Attachmate Reflection 14.1 SP1 Attachmate Reflection 14.1 Attachmate Reflection 14.0 SP1 Attachmate Reflection 14.0 |
| Not Vulnerable: |
X.org xrdb 1.0.9 |
Discussion
X.Org xrdb Remote Arbitrary Shell Command Injection Vulnerability
X.Org xrdb is prone to a remote command-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Successful exploitation requires the attackers' ability to login via XDMCP or set a malicious hostname.
Remote attackers can exploit this issue to execute arbitrary shell commands with the privileges of the user running the display manager.
X.Org xrdb versions prior to 1.0.9 are vulnerable.
X.Org xrdb is prone to a remote command-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Successful exploitation requires the attackers' ability to login via XDMCP or set a malicious hostname.
Remote attackers can exploit this issue to execute arbitrary shell commands with the privileges of the user running the display manager.
X.Org xrdb versions prior to 1.0.9 are vulnerable.
Exploit / POC
X.Org xrdb Remote Arbitrary Shell Command Injection Vulnerability
Attackers can exploit this issue using standard tools.
Attackers can exploit this issue using standard tools.
Solution / Fix
X.Org xrdb Remote Arbitrary Shell Command Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Slackware Linux 12.2
Ubuntu Ubuntu Linux 9.10 powerpc
Ubuntu Ubuntu Linux 9.10 lpia
Slackware Linux 13.1
Ubuntu Ubuntu Linux 10.04 powerpc
S.u.S.E. openSUSE 11.4
Ubuntu Ubuntu Linux 9.10 ARM
Ubuntu Ubuntu Linux 9.10 amd64
Mandriva Linux Mandrake 2009.0 x86_64
Slackware Linux x86_64 -current
MandrakeSoft Enterprise Server 5
Ubuntu Ubuntu Linux 8.04 LTS lpia
Slackware Linux 13.0 x86_64
Mandriva Linux Mandrake 2009.0
Ubuntu Ubuntu Linux 10.10 powerpc
Ubuntu Ubuntu Linux 8.04 LTS i386
MandrakeSoft Corporate Server 4.0 x86_64
Solution:
Updates are available. Please see the references for more information.
Slackware Linux 12.2
-
Slackware xrdb-1.0.9-i486-1_slack12.2.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/ xrdb-1.0.9-i486-1_slack12.2.tgz
Ubuntu Ubuntu Linux 9.10 powerpc
-
Ubuntu x11-xserver-utils_7.4+2ubuntu3.1_powerpc.deb
http://ports.ubuntu.com/pool/main/x/x11-xserver-utils/x11-xserver-util s_7.4+2ubuntu3.1_powerpc.deb
Ubuntu Ubuntu Linux 9.10 lpia
-
Ubuntu x11-xserver-utils_7.4+2ubuntu3.1_lpia.deb
http://ports.ubuntu.com/pool/main/x/x11-xserver-utils/x11-xserver-util s_7.4+2ubuntu3.1_lpia.deb
Slackware Linux 13.1
-
Slackware xrdb-1.0.9-i486-1_slack13.1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/ xrdb-1.0.9-i486-1_slack13.1.txz
Ubuntu Ubuntu Linux 10.04 powerpc
-
Ubuntu x11-xserver-utils_7.5+1ubuntu2.1_powerpc.deb
http://ports.ubuntu.com/pool/main/x/x11-xserver-utils/x11-xserver-util s_7.5+1ubuntu2.1_powerpc.deb
S.u.S.E. openSUSE 11.4
-
SuSE xorg-x11-7.6-43.44.1.i586.rpm
http://download.opensuse.org/update/11.4/rpm/i586/xorg-x11-7.6-43.44.1 .i586.rpm -
SuSE xorg-x11-7.6-43.44.1.x86_64.rpm
http://download.opensuse.org/update/11.4/rpm/x86_64/xorg-x11-7.6-43.44 .1.x86_64.rpm -
SuSE xorg-x11-xauth-7.6-43.44.1.i586.rpm
http://download.opensuse.org/update/11.4/rpm/i586/xorg-x11-xauth-7.6-4 3.44.1.i586.rpm -
SuSE xorg-x11-xauth-7.6-43.44.1.x86_64.rpm
http://download.opensuse.org/update/11.4/rpm/x86_64/xorg-x11-xauth-7.6 -43.44.1.x86_64.rpm
Ubuntu Ubuntu Linux 9.10 ARM
-
Ubuntu x11-xserver-utils_7.4+2ubuntu3.1_armel.deb
http://ports.ubuntu.com/pool/main/x/x11-xserver-utils/x11-xserver-util s_7.4+2ubuntu3.1_armel.deb
Ubuntu Ubuntu Linux 9.10 amd64
-
Ubuntu x11-xserver-utils_7.4+2ubuntu3.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/x/x11-xserver-utils/x11-xs erver-utils_7.4+2ubuntu3.1_amd64.deb
Mandriva Linux Mandrake 2009.0 x86_64
-
Mandriva xrdb-1.0.5-2.1mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/
Slackware Linux x86_64 -current
-
Slackware xrdb-1.0.9-x86_64-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/ x/xrdb-1.0.9-x86_64-1.txz
MandrakeSoft Enterprise Server 5
-
Mandriva xrdb-1.0.5-2.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/download/
Ubuntu Ubuntu Linux 8.04 LTS lpia
-
Ubuntu x11-xserver-utils_7.3+2ubuntu0.1_lpia.deb
http://ports.ubuntu.com/pool/main/x/x11-xserver-utils/x11-xserver-util s_7.3+2ubuntu0.1_lpia.deb
Slackware Linux 13.0 x86_64
-
Slackware xrdb-1.0.9-x86_64-1_slack13.0.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/package s/xrdb-1.0.9-x86_64-1_slack13.0.txz
Mandriva Linux Mandrake 2009.0
-
Mandriva xrdb-1.0.5-2.1mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/
Ubuntu Ubuntu Linux 10.10 powerpc
-
Ubuntu x11-xserver-utils_7.5+2ubuntu1.1_powerpc.deb
http://ports.ubuntu.com/pool/main/x/x11-xserver-utils/x11-xserver-util s_7.5+2ubuntu1.1_powerpc.deb
Ubuntu Ubuntu Linux 8.04 LTS i386
-
Ubuntu x11-xserver-utils_7.3+2ubuntu0.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/x/x11-xserver-utils/x11-xs erver-utils_7.3+2ubuntu0.1_i386.deb
MandrakeSoft Corporate Server 4.0 x86_64
-
Mandriva lib64xorg-x11-6.9.0-5.19.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64xorg-x11-devel-6.9.0-5.19.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64xorg-x11-static-devel-6.9.0-5.19.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva X11R6-contrib-6.9.0-5.19.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva xorg-x11-100dpi-fonts-6.9.0-5.19.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva xorg-x11-6.9.0-5.19.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva xorg-x11-75dpi-fonts-6.9.0-5.19.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva xorg-x11-cyrillic-fonts-6.9.0-5.19.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva xorg-x11-doc-6.9.0-5.19.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva xorg-x11-glide-module-6.9.0-5.19.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva xorg-x11-server-6.9.0-5.19.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva xorg-x11-xauth-6.9.0-5.19.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva xorg-x11-Xdmx-6.9.0-5.19.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva xorg-x11-xfs-6.9.0-5.19.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva xorg-x11-Xnest-6.9.0-5.19.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva xorg-x11-Xprt-6.9.0-5.19.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva xorg-x11-Xvfb-6.9.0-5.19.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/
References
X.Org xrdb Remote Arbitrary Shell Command Injection Vulnerability
References:
References:
- CVE-2011-0465 Improper Input Validation vulnerability in X.Org (Oracle)
- Security Updates and Reflection (Attachmate)
- X Window System Version 11 Release 7.6 (X.Org)
- X.Org Homepage (X.Org)
- xrdb Homepage (X.org)
- ASA-2011-144 xorg-x11 security update (RHSA-2011-0432) (Avaya)
- ASA-2011-145 xorg-x11-server-utils security update (RHSA-2011-0433) (Avaya)
- X.Org security advisory: root hole via rogue hostname (X.Org)
- Xerox Security Bulletin XRX13-007 (Xerox)
- xrdb Chnagelog (cgit)