Lucene search

K
nvd[email protected]NVD:CVE-2006-5214
HistoryOct 10, 2006 - 4:06 a.m.

CVE-2006-5214

2006-10-1004:06:00
web.nvd.nist.gov
2

CVSS2

1.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:H/Au:N/C:P/I:N/A:N

AI Score

6

Confidence

Low

EPSS

0.001

Percentile

28.8%

Race condition in the Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060225, and Solaris 8 through 10 before 20061006, causes a user’s Xsession errors file to have weak permissions before a chmod is performed, which allows local users to read Xsession errors files of other users.

Affected configurations

NVD
Node
netbsdnetbsdMatch3.0
OR
netbsdnetbsdMatch3.99.15
OR
sunsolarisMatch9.0sparc
OR
sunsolarisMatch10.0sparc
OR
sunsunosMatch5.8

CVSS2

1.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:H/Au:N/C:P/I:N/A:N

AI Score

6

Confidence

Low

EPSS

0.001

Percentile

28.8%