First published: Mon Aug 14 2006(Updated: )
The libXm library in LessTif 0.95.0 and earlier allows local users to gain privileges via the DEBUG_FILE environment variable, which is used to create world-writable files when libXm is run from a setuid program.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
lesstif | =0.93.94 | |
lesstif | <=0.95.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4124 is considered a high severity vulnerability due to the potential for local privilege escalation.
To fix CVE-2006-4124, upgrade LessTif to version 0.95.1 or later, where this vulnerability has been addressed.
Local users running LessTif versions up to and including 0.95.0 are affected by CVE-2006-4124.
CVE-2006-4124 is caused by the DEBUG_FILE environment variable leading to the creation of world-writable files in setuid programs.
No, CVE-2006-4124 is a local vulnerability that requires access to the affected system to exploit.