CVE-2006-5214
EPSS 0.08%
Description
Race condition in the Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060225, and Solaris 8 through 10 before 20061006, causes a user's Xsession errors file to have weak permissions before a chmod is performed, which allows local users to read Xsession errors files of other users.
How to fix CVE-2006-5214
To remediate CVE-2006-5214, upgrade the affected package to a fixed version below.
- Debian/xdm—upgrade to 1:1.0.5-1 or later
- Debian/xorg—upgrade to 1:7.1.0-13 or later
Is CVE-2006-5214 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 1:1.0.5-1
- from 0, < 1:7.1.0-13