Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2007-5958Sensitive Information Exposure in Xserver

Severity
5.0MEDIUMNVD
EPSS
3.6%
top 12.21%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJan 18
Latest updateMay 1

Description

X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in the -sp option to the X program, which produces different error messages depending on whether the filename exists.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDx.org/xserver1.4
Debianx.org/xorg-server< 2:1.4.1~git20080105-2+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-5jgc-m9p6-5f9w: X2022-05-01
CVEList
CVE-2007-5958: X2008-01-18
OSV
CVE-2007-5958: X2008-01-18

💥Exploits & PoCs

1
Exploit-DB
X.Org xorg-server 1.1.1-48.13 - Probe for Files (PoC)2008-02-19

📋Vendor Advisories

3
Ubuntu
X.org vulnerabilities2008-01-18
Red Hat
Xorg / XFree86 file existence disclosure vulnerability2008-01-17
Debian
CVE-2007-5958: xorg-server - X.Org Xserver before 1.4.1 allows local users to determine the existence of arbi...2007

💬Community

1
Bugzilla
CVE-2007-5958 Xorg / XFree86 file existence disclosure vulnerability2007-11-20
CVE-2007-5958 — Sensitive Information Exposure | cvebase