Vulnerability Name: | CVE-2006-5397 (CCN-29956) | ||||||||
Assigned: | 2006-10-30 | ||||||||
Published: | 2006-10-30 | ||||||||
Updated: | 2017-07-20 | ||||||||
Summary: | The Xinput module (modules/im/ximcp/imLcIm.c) in X.Org libX11 1.0.2 and 1.0.3 opens a file for reading twice using the same file descriptor, which causes a file descriptor leak that allows local users to read files specified by the XCOMPOSEFILE environment variable via the duplicate file descriptor. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N) 1.8 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
1.8 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-5397 Source: CCN Type: Freedesktop libX11 GIT Repository LibX11 Source: CONFIRM Type: UNKNOWN http://gitweb.freedesktop.org/?p=xorg/lib/libX11.git;a=commit;h=686bb8b35acf6cecae80fe89b2b5853f5816ce19 Source: CCN Type: SA22642 libX11 XCOMPOSEFILE File Descriptor Leak Source: SECUNIA Type: Vendor Advisory 22642 Source: SECUNIA Type: UNKNOWN 22749 Source: MANDRIVA Type: UNKNOWN MDKSA-2006:199 Source: CCN Type: OSVDB ID: 30161 X.Org X Window System (X11) libx11 Xinput Module XCOMPOSEFILE Environment Variable File Descriptor Leak Source: BID Type: UNKNOWN 20845 Source: CCN Type: BID-20845 X.Org X Window Server LibX11 Xinput File Descriptor Leak Vulnerability Source: VUPEN Type: UNKNOWN ADV-2006-4289 Source: CCN Type: freedesktop.org Bugzilla Bug 8699 input method module leaks fd Source: CONFIRM Type: Patch https://bugs.freedesktop.org/show_bug.cgi?id=8699 Source: XF Type: UNKNOWN libx11-xinput-information-disclosure(29956) Source: XF Type: UNKNOWN libx11-xinput-information-disclosure(29956) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |