Vulnerability CVE-2006-0745


Published: 2006-03-20   Modified: 2012-02-12

Description:
X.Org server (xorg-server) 1.0.0 and later, X11R6.9.0, and X11R7.0 inadvertently treats the address of the geteuid function as if it is the return value of a call to geteuid, which allows local users to bypass intended restrictions and (1) execute arbitrary code via the -modulepath command line option or (2) overwrite arbitrary files via -logfile.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
X.Org Security Advisory: privilege escalation and DoS in X11R6.9, X11R7.0
Daniel Stone
20.03.2006
High
xorg-x11-server modulepath Local Privilege Escalation
Marco Ivaldi
03.12.2018

Type:

CWE-Other

Vendor: Redhat
Product: Fedora core 
Version: core_5.0;
Vendor: X.org
Product: X11r6 
Version: 6.9;
Product: X11r7 
Version: 1.0.1; 1.0;
Vendor: Mandrakesoft
Product: Mandrake linux 
Version: 2006;
Vendor: SUN
Product: Solaris 
Version: 10.0;
Vendor: SUSE
Product: Suse linux 
Version: 10.0;

CVSS2 => (AV:L/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.2/10
10/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete

 References:
http://securityreason.com/securityalert/606
http://securitytracker.com/id?1015793
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102252-1
http://support.avaya.com/elmodocs2/security/ASA-2006-078.htm
http://www.mandriva.com/security/advisories?name=MDKSA-2006:056
http://www.novell.com/linux/security/advisories/2006_16_xorgx11server.html
http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00026.html
http://www.securityfocus.com/archive/1/428183/100/0/threaded
http://www.securityfocus.com/archive/1/428230/100/0/threaded
http://www.securityfocus.com/bid/17169
http://www.vupen.com/english/advisories/2006/1017
http://www.vupen.com/english/advisories/2006/1028
https://exchange.xforce.ibmcloud.com/vulnerabilities/25341
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1697

Related CVE
CVE-2019-3688
The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.1 and in SUSE Linux Enterprise Server 12 before and including 3.5.21-26.17.1 had squid:root, 0750 permissions. This allowed an att...
CVE-2019-3684
SUSE Manager until version 4.0.7 and Uyuni until commit 1b426ad5ed0a7191a6fb46bb83e98ae4b99a5ade created world-readable swap files on systems that don't have a swap already configured and don't have btrfs as filesystem
CVE-2019-6690
python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended. To perform the attack, the passphrase to gnupg must be controlled by the adversary and the ciphertext should be trusted. Related to a "CWE...
CVE-2017-16232
** DISPUTED ** LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the ...
CVE-2019-9211
There is a reachable assertion abort in the function write_long_string_missing_values() in data/sys-file-writer.c in libdata.a in GNU PSPP 1.2.0 that will lead to denial of service.
CVE-2018-16876
ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data.
CVE-2018-17957
The YaST2 RMT module for configuring the SUSE Repository Mirroring Tool (RMT) before 1.1.2 exposed MySQL database passwords on process commandline, allowing local attackers to access or corrupt the RMT database.
CVE-2018-19655
A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a malicio...

Copyright 2019, cxsecurity.com

 

Back to Top