First published: Thu Jul 24 2014(Updated: )
Directory traversal vulnerability in tools/backlight_helper.c in X.Org xf86-video-intel 2.99.911 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the interface name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xf86-video-intel | =2.99.911 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-4910 is classified as medium due to the potential for arbitrary file creation or overwrite.
To fix CVE-2014-4910, update to a later version of the xf86-video-intel package that has addressed this vulnerability.
CVE-2014-4910 is caused by a directory traversal vulnerability in tools/backlight_helper.c allowing attackers to manipulate interface names.
CVE-2014-4910 affects users of X.Org xf86-video-intel version 2.99.911.
Yes, CVE-2014-4910 can be exploited remotely, allowing attackers to create or overwrite arbitrary files.