CVE-2011-4028
published 2012-07-03CVE-2011-4028: The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to determine the existence of arbitrary files via a symlink attack on a…
low1.2CVSS 3.1
AVLACHAuNCPINAN
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to determine the existence of arbitrary files via a symlink attack on a temporary lock file, which is handled differently if the file exists.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xorg-server | < xorg-server 2:1.11.1.901-2 (bookworm) | xorg-server 2:1.11.1.901-2 (bookworm) |
| x.org | x_server | <= 1.11.1 | — |
| x.org | x_server | — | — |
| x.org | xorg-server | >= 0 < 2:1.11.1.901-2 | 2:1.11.1.901-2 |
| x.org | xorg-server | >= 0 < 2:1.11.1.901-2 | 2:1.11.1.901-2 |
| x.org | xorg-server | >= 0 < 2:1.11.1.901-2 | 2:1.11.1.901-2 |
| x.org | xorg-server | >= 0 < 2:1.11.1.901-2 | 2:1.11.1.901-2 |
CVSS provenance
nvd1.2LOWAV:L/AC:H/Au:N/C:P/I:N/A:N
osv1.2LOW