X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans, and xterm, does not check the return values for setuid and seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail, such as by exceeding a ulimit.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1193-1 | New XFree86 packages fix several vulnerabilities |
EUVD |
EUVD-2006-4435 | X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans, and xterm, does not check the return values for setuid and seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail, such as by exceeding a ulimit. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T19:14:46.372Z
Reserved: 2006-08-29T00:00:00
Link: CVE-2006-4447
No data.
Status : Deferred
Published: 2006-08-30T01:04:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2006-4447
No data.
OpenCVE Enrichment
No data.
Debian DSA
EUVD