Vulnerability Name: | CVE-2002-1472 (CCN-10137) | ||||||||
Assigned: | 2002-09-18 | ||||||||
Published: | 2002-09-18 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | Untrusted search path vulnerability in libX11.so in xfree86, when used in setuid or setgid programs, allows local users to gain root privileges via a modified LD_PRELOAD environment variable that points to a malicious module. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: SUSE Type: Patch, Vendor Advisory SuSE-SA:2002:032 Source: MITRE Type: CNA CVE-2002-1472 Source: CONECTIVA Type: UNKNOWN CLA-2002:529 Source: CCN Type: Conectiva Linux Announcement CLSA-2002:529 XFree86 Source: CCN Type: RHSA-2003-066 Updated XFree86 packages provide security and bug fixes Source: CCN Type: RHSA-2003-067 Updated XFree86 packages provide security and bug fixes Source: CCN Type: CIAC Information Bulletin N-110 Red Hat Updated XFree86 Packages Provide Security and Bug Fixes Source: XF Type: Patch, Vendor Advisory xfree86-x11-program-execution(10137) Source: OSVDB Type: UNKNOWN 11922 Source: CCN Type: OSVDB ID: 11922 XFree86 libX11.so LD_PRELOAD Privilege Escalation Source: REDHAT Type: UNKNOWN RHSA-2003:066 Source: REDHAT Type: UNKNOWN RHSA-2003:067 Source: BID Type: Patch, Vendor Advisory 5735 Source: CCN Type: BID-5735 XFree86 libX11.so Local Privilege Escalation Vulnerability Source: CCN Type: XFree86 Web site XFree86(TM): Home Page Source: XF Type: UNKNOWN xfree86-x11-program-execution(10137) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |