Vulnerability Name: | CVE-2006-5214 (CCN-29422) | ||||||||
Assigned: | 2006-10-06 | ||||||||
Published: | 2006-10-06 | ||||||||
Updated: | 2018-10-30 | ||||||||
Summary: | Race condition in the Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060225, and Solaris 8 through 10 before 20061006, causes a user's Xsession errors file to have weak permissions before a chmod is performed, which allows local users to read Xsession errors files of other users. | ||||||||
CVSS v3 Severity: | 2.9 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 1.2 Low (CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:N/A:N) 0.9 Low (Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
0.9 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-5214 Source: CCN Type: NetBSD CVS Repository NetBSD CVS Repository Source: CCN Type: SA22323 Sun Solaris X Display Manager "Xsession" Script Security Issue Source: SECUNIA Type: UNKNOWN 22323 Source: CCN Type: SA22439 X.Org X11 X Display Manager "Xsession" Script Security Issue Source: SECUNIA Type: UNKNOWN 22439 Source: SECUNIA Type: UNKNOWN 22469 Source: CCN Type: SA22992 Avaya CMS Sun Solaris X Display Manager Security Issue Source: SECUNIA Type: UNKNOWN 22992 Source: CCN Type: SECTRACK ID: 1017015 Xdm May Let Local Users View the Error Log Files of a Target User Source: SECTRACK Type: UNKNOWN 1017015 Source: CCN Type: Sun Alert ID: 102652 Security Vulnerability in X Display Manager (xdm(1)) Xsession Script Source: SUNALERT Type: Patch 102652 Source: CONFIRM Type: UNKNOWN http://support.avaya.com/elmodocs2/security/ASA-2006-250.htm Source: CCN Type: ASA-2006-250 Sun Alert Notifications from Sun Weekly Report dated October 07 2006 Source: CONFIRM Type: Patch http://www.netbsd.org/cgi-bin/query-pr-single.pl?number=32804 Source: CCN Type: OSVDB ID: 29578 Multiple Vendor X Display Manager Xsession Script Error File Information Disclosure Source: BID Type: UNKNOWN 20400 Source: CCN Type: BID-20400 X.Org XDM XSession Script Race Condition Vulnerability Source: CCN Type: USN-364-1 Xsession vulnerability Source: UBUNTU Type: UNKNOWN USN-364-1 Source: VUPEN Type: UNKNOWN ADV-2006-3962 Source: CCN Type: X.Org Foundation Web site X.Org Foundation Source: CONFIRM Type: UNKNOWN https://bugs.freedesktop.org/show_bug.cgi?id=5897 Source: XF Type: UNKNOWN xdm-xsession-information-disclosure(29422) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1760 | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |