26%
19%
81%
This vulnerability is addressed in the following product updates: X.org, xdm, 2006-03-17 NetBSD, NetBSD, Current 2006-02-12 Sun, Solaris, 10 2006-10-06
The Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060317, and Solaris 8 through 10 before 20061006, allows local users to overwrite arbitrary files, or read another user's Xsession errors file, via a symlink attack on a /tmp/xses-$USER file.
This vulnerability is addressed in the following product updates: X.org, xdm, 2006-03-17 NetBSD, NetBSD, Current 2006-02-12 Sun, Solaris, 10 2006-10-06
CVSS 2.0 Base Score 2.6. CVSS Attack Vector: local. CVSS Attack Complexity: high. CVSS Vector: (AV:L/AC:H/Au:N/C:P/I:P/A:N).
ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.
If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.