← Back

CVE-2006-5215

nvd nist
Published: Oct 10, 2006Modified: Apr 23, 2026

JSON object

Loading...
2.6
Vector
AV:L/AC:H/Au:N/C:P/I:P/A:N
Exploitability: 1.9 / Impact: 4.9
Source: NVD

Description

The Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060317, and Solaris 8 through 10 before 20061006, allows local users to overwrite arbitrary files, or read another user's Xsession errors file, via a symlink attack on a /tmp/xses-$USER file.

Affected (54)

Products: X.org: Xdm · Netbsd: Netbsd · Sun: Solaris, Sunos
1 product
Xdm
1 product
Netbsd
2 products
Solaris
Sunos
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.0.3
Configuration B
53 vulnerable
Vulnerable SoftwareAffected Versions
Netbsd
Up to current
Version 1.0
Version 1.1
Version 1.2.1
Version 1.2
Version 1.3.1
Version 1.3.2
Version 1.3.3
Version 1.3
Version 1.4.1
Version 1.4.1
Version 1.4.1
Version 1.4.1
Version 1.4.1
Version 1.4.1
Version 1.4.2
Version 1.4.2
Version 1.4.2
Version 1.4.2
Version 1.4.2
Version 1.4.3
Version 1.4
Version 1.4
Version 1.4
Version 1.4
Version 1.4
Version 1.5.1
Version 1.5.2
Version 1.5.3
Version 1.5
Version 1.5
Version 1.5
Version 1.6.1
Version 1.6.2
Version 1.6
Version 1.6 beta
Version 2.0.1
Version 2.0.2
Version 2.0.3
Version 2.0
Version 2.1
Version 3.0
Version 3.99.15
Version 4.0
Sun
Version 10.0
Version 8.0
Version 8.0
Version 8.0 beta
Version 9.0
Version 9.0
Version 9.0 x86_update_2
Sun
Version 5.8
Version 5.9

Timeline

No history available yet.