|
libX11 XCOMPOSEFILE File Descriptor Leak
|
|
|
|
|
Secunia Advisory:
|
SA22642
|
|
|
Release Date:
|
2006-11-01
|
|
|
Critical:
|

Less critical
|
|
Impact:
|
Exposure of sensitive information
|
|
Where:
|
Local system
|
|
Solution Status:
|
Vendor Workaround
|
|
| Software: | X Window System 11 (X11) 7.x
|
| | CVE reference: | CVE-2006-5397 (Secunia mirror)
|
|
|
|
|
|
Description: Kees Cook has reported a vulnerability in libX11, which can be exploited by malicious, local users to disclose potentially sensitive information.
The vulnerability is caused due to a file descriptor leak in the Xinput module, which can be exploited to disclose the content of certain files.
The vulnerability is reported in libX11 1.0.2 and 1.0.3. Other versions may also be affected.
Solution: Fixed in the GIT repository.
Provided and/or discovered by: Kees Cook, Ubuntu
Original Advisory: https://bugs.freedesktop.org/show_bug.cgi?id=8699
|
|
|
|
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
|
12 Related Secunia Security Advisories, displaying 10
|
|
|
1. X.org X11 Multiple Vulnerabilities
|
|
2. X.org X11 Multiple Vulnerabilities
|
|
3. X.Org X11 X Font Server Multiple Vulnerabilities
|
|
4. X.org X11 Composite Pixmap Privilege Escalation Vulnerability
|
|
5. X.Org X11 Multiple Vulnerabilities
|
|
6. X.Org X11 "DBE" and "Render" Extensions Vulnerabilities
|
|
7. X.Org X11 X Display Manager "Xsession" Script Security Issue
|
|
8. X11 libXfont CID Encoded Fonts Integer Overflows
|
|
9. X.Org X11 setuid Security Issues
|
|
10. X11 libXfont PCF Integer Overflow Vulnerability
|
Show all related advisories
|
|
|
Send Feedback to Secunia
|
|
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.
|
|
|
|