CVE-2011-4029
published 2012-07-03CVE-2011-4029: The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to change the permissions of arbitrary files to 444, read those files…
PriorityP415low1.9CVSS 2.0
AVLACMAuNCPINAN
EXPLOIT
EPSS
0.60%
45.4th percentile
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to change the permissions of arbitrary files to 444, read those files, and possibly cause a denial of service (removed execution permission) via a symlink attack on a temporary lock file.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xorg-server | < xorg-server 2:1.11.1.901-2 (bookworm) | xorg-server 2:1.11.1.901-2 (bookworm) |
| x.org | x_server | <= 1.11.1 | — |
| x.org | x_server | — | — |
| x.org | xorg-server | >= 0 < 2:1.11.1.901-2 | 2:1.11.1.901-2 |
| x.org | xorg-server | >= 0 < 2:1.11.1.901-2 | 2:1.11.1.901-2 |
| x.org | xorg-server | >= 0 < 2:1.11.1.901-2 | 2:1.11.1.901-2 |
| x.org | xorg-server | >= 0 < 2:1.11.1.901-2 | 2:1.11.1.901-2 |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv1.9LOW
vendor_ubuntu8.5HIGH
vendor_debian1.9LOW
vendor_redhat1.9LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
X.Org X server vulnerability
vendor_ubuntu·2011-10-20·CVSS 8.5
CVE-2010-4818 [HIGH] X.Org X server vulnerability
Title: X.Org X server vulnerability
Summary: The X server could be made to crash or run programs as an administrator.
USN-1232-1 fixed vulnerabilities in the X.Org X server. A regression was
found on Ubuntu 10.04 LTS that affected GLX support, and USN-1232-2 was
released to temporarily disable the problematic security fix. This update
includes a revised fix for CVE-2010-4818.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the X server incorrectly handled certain malformed
input. An authorized attacker could exploit this to cause the X server to
crash, leading to a denial or service, or possibly execute arbitrary code
with root privileges. This issue only affected Ubuntu 10.04 LTS and 10.10.
(CVE-2010-4818)
It was discovered that the X server inc
Ubuntu
X.Org X server regression
vendor_ubuntu·2011-10-19·CVSS 8.5
CVE-2010-4818 [HIGH] X.Org X server regression
Title: X.Org X server regression
Summary: USN-1232-1 caused a regression with GLX support.
USN-1232-1 fixed vulnerabilities in the X.Org X server. A regression was
found on Ubuntu 10.04 LTS that affected GLX support.
This update temporarily disables the fix for CVE-2010-4818 that introduced
the regression.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the X server incorrectly handled certain malformed
input. An authorized attacker could exploit this to cause the X server to
crash, leading to a denial or service, or possibly execute arbitrary code
with root privileges. This issue only affected Ubuntu 10.04 LTS and 10.10.
(CVE-2010-4818)
It was discovered that the X server incorrectly handled certain malformed
input. An authorized attacker could
Red Hat
xorg-x11-server: lock file chmod change race condition
vendor_redhat·2011-10-18·CVSS 1.9
CVE-2011-4029 [LOW] xorg-x11-server: lock file chmod change race condition
xorg-x11-server: lock file chmod change race condition
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to change the permissions of arbitrary files to 444, read those files, and possibly cause a denial of service (removed execution permission) via a symlink attack on a temporary lock file.
Package: xorg-x11 (Red Hat Enterprise Linux 4) - Will not fix
Package: xorg-x11-server (Red Hat Enterprise Linux 5) - Not affected
Ubuntu
X.Org X server vulnerabilities
vendor_ubuntu·2011-10-18·CVSS 8.5
CVE-2011-4029 [HIGH] X.Org X server vulnerabilities
Title: X.Org X server vulnerabilities
Summary: The X server could be made to crash, run programs as an administrator, or
read arbitrary files.
It was discovered that the X server incorrectly handled certain malformed
input. An authorized attacker could exploit this to cause the X server to
crash, leading to a denial or service, or possibly execute arbitrary code
with root privileges. This issue only affected Ubuntu 10.04 LTS and 10.10.
(CVE-2010-4818)
It was discovered that the X server incorrectly handled certain malformed
input. An authorized attacker could exploit this to cause the X server to
crash, leading to a denial or service, or possibly read arbitrary data from
the X server process. This issue only affected Ubuntu 10.04 LTS.
(CVE-2010-4819)
Vladz discovered that the X server
Debian
CVE-2011-4029: xorg-server - The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows loca...
vendor_debian·2011·CVSS 1.9
CVE-2011-4029 [LOW] CVE-2011-4029: xorg-server - The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows loca...
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to change the permissions of arbitrary files to 444, read those files, and possibly cause a denial of service (removed execution permission) via a symlink attack on a temporary lock file.
Scope: local
bookworm: resolved (fixed in 2:1.11.1.901-2)
bullseye: resolved (fixed in 2:1.11.1.901-2)
forky: resolved (fixed in 2:1.11.1.901-2)
sid: resolved (fixed in 2:1.11.1.901-2)
trixie: resolved (fixed in 2:1.11.1.901-2)
GHSA
GHSA-mq85-mwhp-wv55: The LockServer function in os/utils
ghsa_unreviewed·2022-05-13
CVE-2011-4029 [LOW] CWE-362 GHSA-mq85-mwhp-wv55: The LockServer function in os/utils
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to change the permissions of arbitrary files to 444, read those files, and possibly cause a denial of service (removed execution permission) via a symlink attack on a temporary lock file.
OSV
CVE-2011-4029: The LockServer function in os/utils
osv·2012-07-03·CVSS 1.9
CVE-2011-4029 [LOW] CVE-2011-4029: The LockServer function in os/utils
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to change the permissions of arbitrary files to 444, read those files, and possibly cause a denial of service (removed execution permission) via a symlink attack on a temporary lock file.
No detection rules found.
Bugzilla
CVE-2011-4028 CVE-2011-4029 xorg-x11-server various flaws [fedora-15]
bugzilla·2012-03-02·CVSS 1.2
CVE-2011-4028 [LOW] CVE-2011-4028 CVE-2011-4029 xorg-x11-server various flaws [fedora-15]
CVE-2011-4028 CVE-2011-4029 xorg-x11-server various flaws [fedora-15]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=
Bugzilla
CVE-2011-4029 xorg-x11-server: lock file chmod change race condition
bugzilla·2011-10-11·CVSS 1.9
CVE-2011-4029 [LOW] CVE-2011-4029 xorg-x11-server: lock file chmod change race condition
CVE-2011-4029 xorg-x11-server: lock file chmod change race condition
A time-of-check, time-of-use (TOCTOU) race condition was found in the way X.Org X11 X server performed management of temporary lock files. After opening the temporary lock file for writing, the X.Org X11 X server did not recheck if the originally opened file still refers to the same file on disc prior relaxing permissions on the file. A local attacker could use this flaw to conduct symlink attacks (involving the X.Org X11 X server temporary lock file instance) and set the read permissions for all users on any file or directory, leading to disclosure of sensitive information.
Note:
For the exploit to succeed the local attacker needs to be able to run the X.Org X11 X server.
Discussion:
Acknowledgements:
Red Hat would
http://cgit.freedesktop.org/xorg/xserver/commit/?id=b67581cf825940fdf52bf2e0af4330e695d724a4http://lists.freedesktop.org/archives/xorg/2011-October/053680.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0939.htmlhttp://secunia.com/advisories/46460http://secunia.com/advisories/49579http://cgit.freedesktop.org/xorg/xserver/commit/?id=b67581cf825940fdf52bf2e0af4330e695d724a4http://lists.freedesktop.org/archives/xorg/2011-October/053680.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0939.htmlhttp://secunia.com/advisories/46460http://secunia.com/advisories/49579
2012-07-03
Published