Vulnerability Description
The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a privilege escalation during package installation.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian | X11-Common | < 1\:7.6\+12 |
| Debian | Debian Linux | 8.0 |
Related Weaknesses (CWE)
References
- http://vladz.devzero.fr/012_x11-common-vuln.htmlExploitThird Party Advisory
- http://www.openwall.com/lists/oss-security/2012/02/29/1ExploitMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2012/03/01/1Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/cve-2012-1093Broken Link
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430
- https://security-tracker.debian.org/tracker/CVE-2012-1093Vendor Advisory
- http://vladz.devzero.fr/012_x11-common-vuln.htmlExploitThird Party Advisory
- http://www.openwall.com/lists/oss-security/2012/02/29/1ExploitMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2012/03/01/1Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/cve-2012-1093Broken Link
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430
- https://security-tracker.debian.org/tracker/CVE-2012-1093Vendor Advisory
FAQ
What is CVE-2012-1093?
CVE-2012-1093 is a vulnerability with a CVSS score of 7.8 (HIGH). The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a privilege escalation during package installation.
How severe is CVE-2012-1093?
CVE-2012-1093 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-1093?
Check the references section above for vendor advisories and patch information. Affected products include: Debian X11-Common, Debian Debian Linux.