Race condition in the Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060225, and Solaris 8 through 10 before 20061006, causes a users Xsession errors file to have weak permissions before a chmod is performed, which allows local users to read Xsession errors files of other users.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Netbsd | Netbsd | 3.0 (including) | 3.0 (including) |
Netbsd | Netbsd | 3.99.15 (including) | 3.99.15 (including) |
Solaris | Sun | 9.0 (including) | 9.0 (including) |
Solaris | Sun | 10.0 (including) | 10.0 (including) |
Sunos | Sun | 5.8 (including) | 5.8 (including) |
Xinit | Ubuntu | dapper | * |
Xinit | Ubuntu | edgy | * |
Xinit | Ubuntu | feisty | * |
Xorg | Ubuntu | dapper | * |
Xorg | Ubuntu | devel | * |
Xorg | Ubuntu | edgy | * |
Xorg | Ubuntu | feisty | * |