|
SCO OpenServer StartX Weak XHost Permissions Vulnerability
OpenServer is a Unix based operating system distributed by Santa Cruz Operations. A problem in access control of the X server could allow a local user to gain elevated privileges. When the X Window System is started via the xhost script, insufficient xhost access control allows a user to execute commands on the desktop. This can be exploited by setting the display environment variable, and using the tellxdt3 program. This problem makes it possible for a local user to execute commands as root. |
|
|
Privacy Statement |