OSVDB ID: 24000

Title: X.Org / X11 -modulepath Parameter Privileged Code Execution

Info

Disclosure

Mar 20, 2006

Discovery

Unknown

Dates

Exploit

Mar 20, 2006

Solution

Unknown

Description

Freedesktop.org Xorg server contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when the xorg server does not properly verify the user id of the user allowing non root users access to the -modulepath parameter allowing them to execute arbitrary code on the system. This flaw may lead to a loss of Integrity.

Classification

Location: Local Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Public
Disclosure: OSVDB Verified

Solution

Upgrade to version 1.0.2 or higher, as it has been reported to fix this vulnerability. In addition, freedesktop.org has released a patch for some older versions.

Products

Freedesktop.org

Xorg Server

1.0.0
1.0.1

X11

R6.9.0
R7.0

References

Credit

  • Daniel Stone - danielfooishbar.org - freedesktop.org


Direct URL: http://osvdb.org/24000