CVE-2006-4124: Medium severity LessTif LessTif vulnerability
The libXm library in LessTif 0.95.0 and earlier allows local users to gain privileges via the DEBUGFILE environment variable, which is used to create world-writable files when libXm is run from a setuid program.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4124?
CVE-2006-4124 is considered a high severity vulnerability due to the potential for local privilege escalation.
How do I fix CVE-2006-4124?
To fix CVE-2006-4124, upgrade LessTif to version 0.95.1 or later, where this vulnerability has been addressed.
Who is affected by CVE-2006-4124?
Local users running LessTif versions up to and including 0.95.0 are affected by CVE-2006-4124.
What causes CVE-2006-4124?
CVE-2006-4124 is caused by the DEBUG_FILE environment variable leading to the creation of world-writable files in setuid programs.
Is CVE-2006-4124 a remote vulnerability?
No, CVE-2006-4124 is a local vulnerability that requires access to the affected system to exploit.