Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

SCO OpenServer StartX Weak XHost Permissions Vulnerability

OpenServer is a Unix based operating system distributed by Santa Cruz Operations.

A problem in access control of the X server could allow a local user to gain elevated privileges. When the X Window System is started via the xhost script, insufficient xhost access control allows a user to execute commands on the desktop. This can be exploited by setting the display environment variable, and using the tellxdt3 program.

This problem makes it possible for a local user to execute commands as root.







 

Privacy Statement
Copyright 2008, SecurityFocus