CVE-2006-5215: Low severity x.org xdm vulnerability
The Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060317, and Solaris 8 through 10 before 20061006, allows local users to overwrite arbitrary files, or read another user's Xsession errors file, via a symlink attack on a /tmp/xses-$USER file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5215?
CVE-2006-5215 is considered a high-severity vulnerability due to the potential for local users to exploit it to overwrite arbitrary files.
How do I fix CVE-2006-5215?
To fix CVE-2006-5215, ensure that the affected systems are updated to the latest patches provided by NetBSD, X.Org, or Solaris.
Which systems are affected by CVE-2006-5215?
CVE-2006-5215 affects versions of X Display Manager in NetBSD prior to 20060212, X.Org prior to 20060317, and Solaris 8 through 10 before 20061006.
What is a symlink attack related to CVE-2006-5215?
A symlink attack in CVE-2006-5215 allows local users to create symbolic links that manipulate the behavior of the Xsession script, potentially leading to unauthorized file access.
Can users access another user’s Xsession errors file due to CVE-2006-5215?
Yes, CVE-2006-5215 allows local users to read another user's Xsession errors file through exploitation of the vulnerability.