OSVDB ID: 24001

Title: X.Org / X11 -logfile Parameter Arbitrary File Overwrite

Info

Disclosure

Mar 20, 2006

Discovery

Unknown

Dates

Exploit

Mar 20, 2006

Solution

Unknown

Description

Freedesktop.org Xorg server contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when the xorg server does not properly verify the user id of the user allowing non root users access to the -logfile parameter. This then allows them to overwrite arbitrary files on the system and may lead to a loss of Integrity.

Classification

Location: Local Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Public
Disclosure: OSVDB Verified

Solution

Upgrade to version 1.0.2 or higher, as it has been reported to fix this vulnerability. In addition, freedesktop.org has released a patch for some older versions.

Products

Freedesktop.org

Xorg Server

1.0.0
1.0.1

X11

R6.9.0
R7.0

References

Credit

  • Daniel Stone - danielfooishbar.org - freedesktop.org


Direct URL: http://osvdb.org/24001