X.Org xserver Local File Permission Vulnerability Exploiting LockServer Function
CVE-2011-4029

Currently unrated

Key Information:

Vendor

X.org

Status
Vendor
CVE Published:
3 July 2012

What is CVE-2011-4029?

The LockServer function in the X.Org xserver prior to version 1.11.2 is vulnerable to a security flaw that allows local users to manipulate the permissions of arbitrary files. This vulnerability can be exploited through a symlink attack targeting a temporary lock file, enabling attackers to change file permissions to 444, thereby restricting execution and leading to a potential denial of service.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.