7.2

CVE-2006-0745

Exploit

X.Org server (xorg-server) 1.0.0 and later, X11R6.9.0, and X11R7.0 inadvertently treats the address of the geteuid function as if it is the return value of a call to geteuid, which allows local users to bypass intended restrictions and (1) execute arbitrary code via the -modulepath command line option or (2) overwrite arbitrary files via -logfile.

Data is provided by the National Vulnerability Database (NVD)
X.OrgX11r6 Version6.9
X.OrgX11r7 Version1.0
X.OrgX11r7 Version1.0.1
MandrakesoftMandrake Linux Version2006
MandrakesoftMandrake Linux Version2006 Editionx86_64
RedhatFedora Core Versioncore_5.0
SunSolaris Version10.0 Editionx86
SuseSuse Linux Version10.0 Editionoss
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.18% 0.396
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C