Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.850164
Category:SuSE Local Security Checks
Title:SUSE: Security Advisory for xorg-x11 (SUSE-SA:2011:016)
Summary:The remote host is missing an update for the 'xorg-x11'; package(s) announced via the referenced advisory.
Description:Summary:
The remote host is missing an update for the 'xorg-x11'
package(s) announced via the referenced advisory.

Vulnerability Insight:
The xrdb helper program of the xorg-x11 package passes untrusted input
such as hostnames retrieved via DHCP or client hostnames of XDMCP sessions
to popen() without sanitization.
Therefore, remote attackers could execute arbitrary commands as root by
assigning specially crafted hostnames to X11 servers or to XDMCP clients.
CVE-2011-0465 has been assigned to this issue.

Vulnerability Impact:
remote code execution

Affected Software/OS:
xorg-x11 on openSUSE 11.2, openSUSE 11.3, SUSE SLES 9

Solution:
Please install the updated package(s).

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-0465
BugTraq ID: 47189
http://www.securityfocus.com/bid/47189
Debian Security Information: DSA-2213 (Google Search)
http://www.debian.org/security/2011/dsa-2213
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057928.html
http://www.mandriva.com/security/advisories?name=MDVSA-2011:076
http://lists.freedesktop.org/archives/xorg-announce/2011-April/001636.html
http://lists.freedesktop.org/archives/xorg-announce/2011-April/001635.html
http://www.redhat.com/support/errata/RHSA-2011-0432.html
http://www.redhat.com/support/errata/RHSA-2011-0433.html
http://www.securitytracker.com/id?1025317
http://secunia.com/advisories/44010
http://secunia.com/advisories/44012
http://secunia.com/advisories/44040
http://secunia.com/advisories/44082
http://secunia.com/advisories/44122
http://secunia.com/advisories/44123
http://secunia.com/advisories/44193
http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.465748
SuSE Security Announcement: SUSE-SA:2011:016 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00002.html
SuSE Security Announcement: openSUSE-SU-2011:0298 (Google Search)
https://lwn.net/Articles/437150/
http://www.ubuntu.com/usn/USN-1107-1
http://www.vupen.com/english/advisories/2011/0880
http://www.vupen.com/english/advisories/2011/0889
http://www.vupen.com/english/advisories/2011/0906
http://www.vupen.com/english/advisories/2011/0929
http://www.vupen.com/english/advisories/2011/0966
http://www.vupen.com/english/advisories/2011/0975
XForce ISS Database: xorg11-xrdb-command-execution(66585)
https://exchange.xforce.ibmcloud.com/vulnerabilities/66585
CopyrightCopyright (C) 2011 Greenbone Networks GmbH

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.