>> X.Org X11 "setuid()" Failures Handling Local Privilege Escalation Vulnerability
Title : X.Org X11 "setuid()" Failures Handling Local Privilege Escalation Vulnerability VUPEN ID : VUPEN/ADV-2006-3409 CVE ID : GENERIC-MAP-NOMATCH
Rated as : Moderate Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-08-29
Technical Description
A vulnerability has been identified in X.Org X11, which could be exploited by malicious users to bypass security restrictions and obtain elevated privileges. This flaw is due to an error where certain applications (e.g. X server, xdm, or xterm) do not check the return code of "setuid()" calls, which could be exploited by local attackers to manipulate arbitrary files or execute commands with root privileges.