Secunia Logo
Netsikker nu! 2008
 
CVE Reference: CVE-2006-5215
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-5215

Description:
The Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060317, and Solaris 8 through 10 before 20061006, allows local users to overwrite arbitrary files, or read another user's Xsession errors file, via a symlink attack on a /tmp/xses-$USER file.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/29427

SUNALERT
  http://sunsolve.sun.com/search/document.do?assetkey=1-26-102652-1

ST
  1017015

SAID
  Secunia Advisory: SA22992

OVAL
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2205

CONFIRM
  http://support.avaya.com/elmodocs2/security/ASA-2006-250.htm
  http://www.netbsd.org/cgi-bin/query-pr-single.pl?number=32805


Return to the previous page.