First published: Tue Jul 03 2012(Updated: )
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to change the permissions of arbitrary files to 444, read those files, and possibly cause a denial of service (removed execution permission) via a symlink attack on a temporary lock file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
X.org X.org | <=1.11.1 | |
X.org X.org | =1.11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4029 has been rated as a medium severity vulnerability due to its potential for local denial of service and permission manipulation.
To mitigate CVE-2011-4029, update the X.Org xserver to version 1.11.2 or later, which contains the necessary patch.
Local users on systems running vulnerable versions of the X.Org xserver, specifically versions before 1.11.2, are at risk from CVE-2011-4029.
CVE-2011-4029 facilitates a symlink attack that could change file permissions and lead to the denial of service.
CVE-2011-4029 can be exploited by local users with knowledge of symlink manipulation, making it relatively easy to exploit in the right conditions.