CVE-2011-4028
published 2012-07-03CVE-2011-4028: The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to determine the existence of arbitrary files via a symlink attack on a…
PriorityP410low1.2CVSS 2.0
AVLACHAuNCPINAN
EPSS
0.37%
29.8th percentile
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to determine the existence of arbitrary files via a symlink attack on a temporary lock file, which is handled differently if the file exists.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xorg-server | < xorg-server 2:1.11.1.901-2 (bookworm) | xorg-server 2:1.11.1.901-2 (bookworm) |
| x.org | x_server | <= 1.11.1 | — |
| x.org | x_server | — | — |
| x.org | xorg-server | >= 0 < 2:1.11.1.901-2 | 2:1.11.1.901-2 |
| x.org | xorg-server | >= 0 < 2:1.11.1.901-2 | 2:1.11.1.901-2 |
| x.org | xorg-server | >= 0 < 2:1.11.1.901-2 | 2:1.11.1.901-2 |
| x.org | xorg-server | >= 0 < 2:1.11.1.901-2 | 2:1.11.1.901-2 |
CVSS provenance
nvdv2.01.2LOWAV:L/AC:H/Au:N/C:P/I:N/A:N
osv1.2LOW
vendor_ubuntu8.5HIGH
vendor_debian1.2LOW
vendor_redhat1.2LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
X.Org X server vulnerability
vendor_ubuntu·2011-10-20·CVSS 8.5
CVE-2010-4818 [HIGH] X.Org X server vulnerability
Title: X.Org X server vulnerability
Summary: The X server could be made to crash or run programs as an administrator.
USN-1232-1 fixed vulnerabilities in the X.Org X server. A regression was
found on Ubuntu 10.04 LTS that affected GLX support, and USN-1232-2 was
released to temporarily disable the problematic security fix. This update
includes a revised fix for CVE-2010-4818.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the X server incorrectly handled certain malformed
input. An authorized attacker could exploit this to cause the X server to
crash, leading to a denial or service, or possibly execute arbitrary code
with root privileges. This issue only affected Ubuntu 10.04 LTS and 10.10.
(CVE-2010-4818)
It was discovered that the X server inc
Ubuntu
X.Org X server regression
vendor_ubuntu·2011-10-19·CVSS 8.5
CVE-2010-4818 [HIGH] X.Org X server regression
Title: X.Org X server regression
Summary: USN-1232-1 caused a regression with GLX support.
USN-1232-1 fixed vulnerabilities in the X.Org X server. A regression was
found on Ubuntu 10.04 LTS that affected GLX support.
This update temporarily disables the fix for CVE-2010-4818 that introduced
the regression.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the X server incorrectly handled certain malformed
input. An authorized attacker could exploit this to cause the X server to
crash, leading to a denial or service, or possibly execute arbitrary code
with root privileges. This issue only affected Ubuntu 10.04 LTS and 10.10.
(CVE-2010-4818)
It was discovered that the X server incorrectly handled certain malformed
input. An authorized attacker could
Ubuntu
X.Org X server vulnerabilities
vendor_ubuntu·2011-10-18·CVSS 8.5
CVE-2011-4029 [HIGH] X.Org X server vulnerabilities
Title: X.Org X server vulnerabilities
Summary: The X server could be made to crash, run programs as an administrator, or
read arbitrary files.
It was discovered that the X server incorrectly handled certain malformed
input. An authorized attacker could exploit this to cause the X server to
crash, leading to a denial or service, or possibly execute arbitrary code
with root privileges. This issue only affected Ubuntu 10.04 LTS and 10.10.
(CVE-2010-4818)
It was discovered that the X server incorrectly handled certain malformed
input. An authorized attacker could exploit this to cause the X server to
crash, leading to a denial or service, or possibly read arbitrary data from
the X server process. This issue only affected Ubuntu 10.04 LTS.
(CVE-2010-4819)
Vladz discovered that the X server
Red Hat
xorg-x11-server: File existence disclosure vulnerability
vendor_redhat·2011-10-18·CVSS 1.2
CVE-2011-4028 [LOW] xorg-x11-server: File existence disclosure vulnerability
xorg-x11-server: File existence disclosure vulnerability
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to determine the existence of arbitrary files via a symlink attack on a temporary lock file, which is handled differently if the file exists.
Package: xorg-x11 (Red Hat Enterprise Linux 4) - Will not fix
Debian
CVE-2011-4028: xorg-server - The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows loca...
vendor_debian·2011·CVSS 1.2
CVE-2011-4028 [LOW] CVE-2011-4028: xorg-server - The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows loca...
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to determine the existence of arbitrary files via a symlink attack on a temporary lock file, which is handled differently if the file exists.
Scope: local
bookworm: resolved (fixed in 2:1.11.1.901-2)
bullseye: resolved (fixed in 2:1.11.1.901-2)
forky: resolved (fixed in 2:1.11.1.901-2)
sid: resolved (fixed in 2:1.11.1.901-2)
trixie: resolved (fixed in 2:1.11.1.901-2)
GHSA
GHSA-43jf-fxqp-3qf7: The LockServer function in os/utils
ghsa_unreviewed·2022-05-13
CVE-2011-4028 [LOW] CWE-59 GHSA-43jf-fxqp-3qf7: The LockServer function in os/utils
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to determine the existence of arbitrary files via a symlink attack on a temporary lock file, which is handled differently if the file exists.
OSV
CVE-2011-4028: The LockServer function in os/utils
osv·2012-07-03·CVSS 1.2
CVE-2011-4028 [LOW] CVE-2011-4028: The LockServer function in os/utils
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to determine the existence of arbitrary files via a symlink attack on a temporary lock file, which is handled differently if the file exists.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-4028 CVE-2011-4029 xorg-x11-server various flaws [fedora-15]
bugzilla·2012-03-02·CVSS 1.2
CVE-2011-4028 [LOW] CVE-2011-4028 CVE-2011-4029 xorg-x11-server various flaws [fedora-15]
CVE-2011-4028 CVE-2011-4029 xorg-x11-server various flaws [fedora-15]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=
Bugzilla
CVE-2011-4028 xorg-x11-server: File existence disclosure vulnerability
bugzilla·2011-10-13·CVSS 1.2
CVE-2011-4028 [LOW] CVE-2011-4028 xorg-x11-server: File existence disclosure vulnerability
CVE-2011-4028 xorg-x11-server: File existence disclosure vulnerability
A file existence disclosure flaw was found in the way X.Org X11 X server performed management of temporary lock files. A local, unprivileged user could use this flaw to confirm (non) existence of a file system object (file, directory or fifo), which shouldn't be accessible for them, via symbolic link attacks, with link name being the expected name of the X.Org X11 X server temporary lock file.
Note:
For the exploit to succeed the local attacker needs to be able to run the X.Org X11 X server.
Discussion:
Acknowledgements:
Red Hat would like to thank researcher with a nickname vladz for reporting this issue.
---
Created attachment 528780
Proposed X.Org X11 server upstream patch
---
This issue is now public. The f
http://cgit.freedesktop.org/xorg/xserver/commit/?id=6ba44b91e37622ef8c146d8f2ac92d708a18ed34http://lists.freedesktop.org/archives/xorg/2011-October/053680.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0939.htmlhttp://secunia.com/advisories/46460http://secunia.com/advisories/49579http://cgit.freedesktop.org/xorg/xserver/commit/?id=6ba44b91e37622ef8c146d8f2ac92d708a18ed34http://lists.freedesktop.org/archives/xorg/2011-October/053680.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0939.htmlhttp://secunia.com/advisories/46460http://secunia.com/advisories/49579
2012-07-03
Published