bugs.debian.org
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=652249 CVE-2011-4613
X.Org xorg 1.4 < 1.11.2 - File Permission Change
Record summary
CVE-2011-4613 has a selected CVSS score of 4.6; EIP currently links 1 catalogued exploit.
Description
The X.Org X wrapper (xserver-wrapper.c) in Debian GNU/Linux and Ubuntu Linux does not properly verify the TTY of a user who is starting X, which allows local users to bypass intended access restrictions by associating stdin with a file that is misinterpreted as the console TTY.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBX.Org xorg 1.4 < 1.11.2 - File Permission ChangeExploitDB exploitby vladzNot analyzed1 file
References
4DSA-2364Vendor advisory
http://www.debian.org/security/2011/dsa-2364 USN-1349-1Vendor advisory
http://www.ubuntu.com/usn/USN-1349-1 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2011-4613