614
VMScore

CVE-2012-1093

Published: 21/02/2020 Updated: 07/11/2023
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The init script in the Debian x11-common package prior to 1:7.6+12 is vulnerable to a symlink attack that can lead to a privilege escalation during package installation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 8.0

debian debian linux 9.0

debian debian linux 10.0

debian x11-common

Vendor Advisories

Debian Bug report logs - #661627 init script x11-common creates directories in insecure manners Package: x11-common; Maintainer for x11-common is Debian X Strike Force <debian-x@listsdebianorg>; Source for x11-common is src:xorg (PTS, buildd, popcon) Reported by: vladz <vladz@devzerofr> Date: Tue, 28 Feb 2012 17:3 ...