XFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.
Software | From | Fixed in |
---|---|---|
xfree86_project / x11r6 | 3.3.3 | 3.3.3.x |
slackware / slackware_linux | 3.5 | 3.5.x |
redhat / linux | 5.1 | 5.1.x |
redhat / linux | 5.2 | 5.2.x |
slackware / slackware_linux | 3.4 | 3.4.x |
netbsd / netbsd | 1.3.3 | 1.3.3.x |
slackware / slackware_linux | 4.0 | 4.0.x |
suse / suse_linux | 5.2 | 5.2.x |
suse / suse_linux | 6.0 | 6.0.x |
suse / suse_linux | 6.1 | 6.1.x |
suse / suse_linux | 5.1 | 5.1.x |
slackware / slackware_linux | 3.6 | 3.6.x |
slackware / slackware_linux | 3.3 | 3.3.x |
netbsd / netbsd | 1.3.2 | 1.3.2.x |