1.9 Low
CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:L/AC:M/Au:N/C:P/I:N/A:N
0.0004 Low
EPSS
Percentile
5.1%
The X Window System is a graphical windowing system based on a client/server model.
vladz reported the following vulnerabilities in the X.Org X server:
A local attacker could exploit these vulnerabilities to disclose information by making arbitrary files on a system world-readable or gain information whether a specified file exists on the system and whether it is a file, directory, or a named pipe.
There is no known workaround at this time.
All X.Org X Server 1.9 users should upgrade to the latest 1.9 version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=x11-base/xorg-server-1.9.5-r1"
All X.Org X Server 1.10 users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=x11-base/xorg-server-1.10.4-r1"
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Gentoo | any | all | x11-base/xorg-server | < 1.10.4-r1 | UNKNOWN |