LWN.net Logo

xorg-x11: arbitrary command execution as root

Package(s):xorg-x11 CVE #(s):CVE-2011-0465
Created:April 6, 2011 Updated:June 13, 2011
Description: From the X.Org advisory:

By crafting hostnames with shell escape characters, arbitrary commands can be executed in a root environment when a display manager reads in the resource database via xrdb.

These specially crafted hostnames can occur in two environments:

  • Hosts that set their hostname via DHCP
  • Hosts that allow remote logins via xdmcp
Alerts:
Fedora FEDORA-2011-4879 2011-04-06
CentOS CESA-2011:0432 2011-04-19
Fedora FEDORA-2011-4871 2011-04-06
CentOS CESA-2011:0433 2011-04-14
SUSE SUSE-SA:2011:016 2011-04-13
Slackware SSA:2011-096-01 2011-04-12
Red Hat RHSA-2011:0433-01 2011-04-11
Red Hat RHSA-2011:0432-01 2011-04-11
Debian DSA-2213-1 2011-04-08
Ubuntu USN-1107-1 2011-04-06
openSUSE openSUSE-SU-2011:0298-1 2011-04-06
Mandriva MDVSA-2011:076 2011-04-21

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds