Title: X.Org X Window System (X11) xrdb xrdb.c Hostname Shell Metacharacter Arbitrary Local Command Injection
Info
Disclosure
Apr 05, 2011
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Apr 05, 2011
Description
X.Org X Window System (X11) contains a flaw in the xrdb component. The issue is due the xrdb tool improperly escaping hostnames. With a specially crafted request containing shell metacharacters, a local attacker can inject arbitrary commands.
Classification
Location:
Local Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
OSVDB:
Authentication Required
Solution
Upgrade to version 1.0.9 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.