Vulnerability Description
dexconf in XFree86 Xserver 4.1.0-2 creates the /dev/dri directory with insecure permissions (666), which allows local users to replace or create files in the root file system.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xfree86 Project | Xfree86 X Server | 4.1.0.2 |
References
- http://groups.google.com/groups?selm=20010829121505.A16004%40compusol.com.auPatchVendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-228529-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1017429.1-1
- http://www.redhat.com/support/errata/RHSA-2003-067.htmlPatchVendor Advisory
- http://groups.google.com/groups?selm=20010829121505.A16004%40compusol.com.auPatchVendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-228529-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1017429.1-1
- http://www.redhat.com/support/errata/RHSA-2003-067.htmlPatchVendor Advisory
FAQ
What is CVE-2001-1409?
CVE-2001-1409 is a vulnerability with a CVSS score of 3.6 (LOW). dexconf in XFree86 Xserver 4.1.0-2 creates the /dev/dri directory with insecure permissions (666), which allows local users to replace or create files in the root file system.
How severe is CVE-2001-1409?
CVE-2001-1409 has been rated LOW with a CVSS base score of 3.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-1409?
Check the references section above for vendor advisories and patch information. Affected products include: Xfree86 Project Xfree86 X Server.