LWN.net Logo

xorg-x11-apps: code execution

Package(s):xorg-x11-apps CVE #(s):CVE-2011-2504
Created:January 17, 2013 Updated:March 15, 2013
Description: From the Red Hat advisory:

It was found that the x11perfcomp utility included the current working directory in its PATH environment variable. Running x11perfcomp in an attacker-controlled directory would cause arbitrary code execution with the privileges of the user running x11perfcomp.

Alerts:
Fedora FEDORA-2013-0124 2013-01-16
Red Hat RHSA-2013:0502-02 2013-02-21
Oracle ELSA-2013-0502 2013-02-25
CentOS CESA-2013:0502 2013-03-09
CentOS CESA-2013:0502 2013-03-09
CentOS CESA-2013:0502 2013-03-09
Scientific Linux SL-NotF-20130314 2013-03-14

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds