XFree86 libX11.so Local Privilege Escalation Vulnerability
BID:5735
Info
XFree86 libX11.so Local Privilege Escalation Vulnerability
| Bugtraq ID: | 5735 |
| Class: | Design Error |
| CVE: |
CVE-2002-1472 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 18 2002 12:00AM |
| Updated: | Mar 19 2015 09:18AM |
| Credit: | Advisory released by SuSE. |
| Vulnerable: |
XFree86 X11R6 4.2 .0 XFree86 X11R6 4.1 .0 SuSE Linux 8.0 Redhat XFree86-Xvfb-4.2.0-72.i386.rpm Redhat XFree86-Xnest-4.2.0-72.i386.rpm Redhat XFree86-xfs-4.2.0-72.i386.rpm Redhat XFree86-xdm-4.2.0-72.i386.rpm Redhat XFree86-xauth-4.2.0-72.i386.rpm Redhat XFree86-twm-4.2.0-72.i386.rpm Redhat XFree86-truetype-fonts-4.2.0-72.i386.rpm Redhat XFree86-tools-4.2.0-72.i386.rpm Redhat XFree86-Mesa-libGLU-4.2.0-72.i386.rpm Redhat XFree86-Mesa-libGL-4.2.0-72.i386.rpm Redhat XFree86-libs-4.2.0-72.i386.rpm Redhat XFree86-ISO8859-9-75dpi-fonts-4.2.0-72.i386.rpm Redhat XFree86-ISO8859-9-100dpi-fonts-4.2.0-72.i386.rpm Redhat XFree86-ISO8859-2-75dpi-fonts-4.2.0-72.i386.rpm Redhat XFree86-ISO8859-2-100dpi-fonts-4.2.0-72.i386.rpm Redhat XFree86-ISO8859-15-75dpi-fonts-4.2.0-72.i386.rpm Redhat XFree86-ISO8859-15-100dpi-fonts-4.2.0-72.i386.rpm Redhat XFree86-font-utils-4.2.0-72.i386.rpm Redhat XFree86-doc-4.2.0-72.i386.rpm Redhat XFree86-devel-4.2.0-72.i386.rpm Redhat XFree86-cyrillic-fonts-4.2.0-72.i386.rpm Redhat XFree86-base-fonts-4.2.0-72.i386.rpm Redhat XFree86-75dpi-fonts-4.2.0-72.i386.rpm Redhat XFree86-4.2.0-72.i386.rpm Redhat XFree86-100dpi-fonts-4.2.0-72.i386.rpm |
| Not Vulnerable: |
XFree86 X11R6 4.2.1 |
Discussion
XFree86 libX11.so Local Privilege Escalation Vulnerability
SuSE has reported a vulnerability in XFree86 that may affect other systems which include it. The xf86 package, which is included in the Suse Linux distribution, contains various programs and libraries that are necessary for X server to run. The package includes the libX11.so library.
When libX11.so is called it will dynamically load libraries via a path defined in a environment variable, controlled by the executing user. libX11.so fails to disable the variable when the process is setuid, allowing for malicious libraries to be loaded. Attackers may cause arbitrary code to be executed with escalated privileges
SuSE has reported a vulnerability in XFree86 that may affect other systems which include it. The xf86 package, which is included in the Suse Linux distribution, contains various programs and libraries that are necessary for X server to run. The package includes the libX11.so library.
When libX11.so is called it will dynamically load libraries via a path defined in a environment variable, controlled by the executing user. libX11.so fails to disable the variable when the process is setuid, allowing for malicious libraries to be loaded. Attackers may cause arbitrary code to be executed with escalated privileges
Exploit / POC
XFree86 libX11.so Local Privilege Escalation Vulnerability
No exploit is required.
No exploit is required.
References
XFree86 libX11.so Local Privilege Escalation Vulnerability
References:
References: