Local privilege escalation vulnerability in XFree86
Package(s):
xf86 xfree86
CVE #(s):
Created:
September 18, 2002
Updated:
October 27, 2002
Description:
XFree86 version 4.2.1 fixes a problem in
Xlib that made it possible to execute arbitrary code in privileged clients.
Other libraries are dynamically loaded by libX11.so as needed.
When linking against a setuid program, arbitrary code
could be loaded and executed from a pathname controlled by the user.