Vulnerability Description
The default configuration of the Xsession file in Mandrake Linux 7.1 and 7.0 bypasses the Xauthority access control mechanism with an "xhost + localhost" command, which allows local users to sniff X Windows events and gain privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mandrakesoft | Mandrake Linux | 7.0 |
References
- http://www.linux-mandrake.com/en/security/MDKSA-2000-052.php3
- http://www.securityfocus.com/archive/1/136495
- http://www.securityfocus.com/bid/1735PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5305
- http://www.linux-mandrake.com/en/security/MDKSA-2000-052.php3
- http://www.securityfocus.com/archive/1/136495
- http://www.securityfocus.com/bid/1735PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5305
FAQ
What is CVE-2000-1059?
CVE-2000-1059 is a vulnerability with a CVSS score of 7.2 (HIGH). The default configuration of the Xsession file in Mandrake Linux 7.1 and 7.0 bypasses the Xauthority access control mechanism with an "xhost + localhost" command, which allows local users to sniff X W...
How severe is CVE-2000-1059?
CVE-2000-1059 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2000-1059?
Check the references section above for vendor advisories and patch information. Affected products include: Mandrakesoft Mandrake Linux.