CVE Vulnerabilities

CVE-2011-4613

Published: Feb 05, 2014 | Modified: Aug 24, 2020
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
5.9 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Ubuntu
MEDIUM

The X.Org X wrapper (xserver-wrapper.c) in Debian GNU/Linux and Ubuntu Linux does not properly verify the TTY of a user who is starting X, which allows local users to bypass intended access restrictions by associating stdin with a file that is misinterpreted as the console TTY.

Affected Software

Name Vendor Start Version End Version
X_server X.org - (including) - (including)
Ubuntu_linux Canonical 10.04 (including) 10.04 (including)
Ubuntu_linux Canonical 10.10 (including) 10.10 (including)
Ubuntu_linux Canonical 11.04 (including) 11.04 (including)
Ubuntu_linux Canonical 11.10 (including) 11.10 (including)
Debian_linux Debian * *
Linux Ubuntu * *
Xorg Ubuntu hardy *
Xorg Ubuntu lucid *
Xorg Ubuntu maverick *
Xorg Ubuntu natty *
Xorg Ubuntu oneiric *
Xorg Ubuntu upstream *

References