LOW · 1.2

CVE-2006-5214

Race condition in the Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060225, and Solaris 8 through 10 before 20061006, causes a user's Xsession errors fi...

Vulnerability Description

Race condition in the Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060225, and Solaris 8 through 10 before 20061006, causes a user's Xsession errors file to have weak permissions before a chmod is performed, which allows local users to read Xsession errors files of other users.

CVSS Score

1.2

LOW

AV:L/AC:H/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
NetbsdNetbsd3.0
SunSolaris9.0
SunSunos5.8

References

FAQ

What is CVE-2006-5214?

CVE-2006-5214 is a vulnerability with a CVSS score of 1.2 (LOW). Race condition in the Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060225, and Solaris 8 through 10 before 20061006, causes a user's Xsession errors fi...

How severe is CVE-2006-5214?

CVE-2006-5214 has been rated LOW with a CVSS base score of 1.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-5214?

Check the references section above for vendor advisories and patch information. Affected products include: Netbsd Netbsd, Sun Solaris, Sun Sunos.