CVE-2012-0871

systemd < 37 - Arbitrary File Write via Symlink Attack on X11 User Directory

Title source: llm
STIX 2.1

Description

The session_link_x11_socket function in login/logind-session.c in systemd-logind in systemd, possibly 37 and earlier, allows local users to create or overwrite arbitrary files via a symlink attack on the X11 user directory in /run/user/.

References (5)

Core 5
Core References
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=795853
Issue Tracking x_refsource_confirm
https://bugzilla.novell.com/show_bug.cgi?id=747154
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/79768

Scores

EPSS 0.0036
EPSS Percentile 27.2%

Details

CWE
CWE-59
Status published
Products (38)
opensuse/opensuse 12.1
systemd_project/systemd 1
systemd_project/systemd 2
systemd_project/systemd 3
systemd_project/systemd 4
systemd_project/systemd 5
systemd_project/systemd 6
systemd_project/systemd 7
systemd_project/systemd 8
systemd_project/systemd 9
... and 28 more
Published Apr 18, 2014
Tracked Since Feb 18, 2026