X.Org X Server X wrapper Local Security Bypass Vulnerability
BID:51082
Info
X.Org X Server X wrapper Local Security Bypass Vulnerability
| Bugtraq ID: | 51082 |
| Class: | Design Error |
| CVE: |
CVE-2011-4613 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 15 2011 12:00AM |
| Updated: | Jan 26 2012 08:30PM |
| Credit: | vladz |
| Vulnerable: |
X.org xorg-server 1:7.5+8 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
X.Org X Server X wrapper Local Security Bypass Vulnerability
X.Org X Server is prone to a local security-bypass vulnerability.
Successful exploits will allow attackers to bypass certain security restrictions and launch X.Org with root privileges.
X.Org X Server is prone to a local security-bypass vulnerability.
Successful exploits will allow attackers to bypass certain security restrictions and launch X.Org with root privileges.
Exploit / POC
X.Org X Server X wrapper Local Security Bypass Vulnerability
Attackers require local interactive access to exploit.
Attackers require local interactive access to exploit.
Solution / Fix
X.Org X Server X wrapper Local Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
X.Org X Server X wrapper Local Security Bypass Vulnerability
References:
References:
- bypass default security level of the X wrapper (vladz)
- X.org Home Page (X.org)