Upstream information
Description
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to change the permissions of arbitrary files to 444, read those files, and possibly cause a denial of service (removed execution permission) via a symlink attack on a temporary lock file.NVD CVSS v2 Base Score: 1.9 (AV:L/AC:M/Au:N/C:P/I:N/A:N)
Novell/SUSE information
Note from the SUSE Security Team
Only openSUSE 11.3 and SUSE Linux Enterprise 11 were affected by this problem and received fixed packages. No other products were affected. Novell Bugzilla entry: 722944 SUSE Security Advisories:- SUSE-SU-2011:1292-1, published Fri, 2 Dec 2011 08:08:16 +0100 (CET)
- openSUSE-SU-2012:0227-1, published Thu, 9 Feb 2012 19:10:34 +0100 (CET)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| openSUSE 11.3 |
| |
| openSUSE 11.3 |
| |
| SLE 11 SP2 DEBUGINFO |
| Builds SAT Patch Nr: 6111 |
| SUSE Linux Enterprise Desktop 11 SP2 SUSE Linux Enterprise Server 11 SP2 SUSE Linux Enterprise Server 11 SP2 for VMware |
| Builds SAT Patch Nr: 6111 |
| SLE 11 SP1 DEBUGINFO |
| sle11-sp1-sdk.ppc sles11-sp1-vmware.x86-64 sles11-sp1.x86 sle11-sp1-sdk.x86 sles11-sp1.s390x sle11-sp1-sdk.x86-64 sles11-sp1.ia64 sled11-sp1.x86 sle11-sp1-sdk.ia64 sled11-sp1.x86-64 sle11-sp1-sdk.s390x sles11-sp1.x86-64 sles11-sp1-vmware.x86 sles11-sp1.ppc SAT Patch Nr: 5479 |
| SUSE Linux Enterprise Software Development Kit 11 SP1 |
| sle11-sp1-sdk.ppc sles11-sp1-vmware.x86-64 sles11-sp1.x86 sle11-sp1-sdk.x86 sles11-sp1.s390x sle11-sp1-sdk.x86-64 sles11-sp1.ia64 sled11-sp1.x86 sle11-sp1-sdk.ia64 sled11-sp1.x86-64 sle11-sp1-sdk.s390x sles11-sp1.x86-64 sles11-sp1-vmware.x86 sles11-sp1.ppc SAT Patch Nr: 5479 |
| SUSE Linux Enterprise Desktop 11 SP1 SUSE Linux Enterprise Server 11 SP1 SUSE Linux Enterprise Server 11 SP1 for VMware |
| sle11-sp1-sdk.ppc sles11-sp1-vmware.x86-64 sles11-sp1.x86 sle11-sp1-sdk.x86 sles11-sp1.s390x sle11-sp1-sdk.x86-64 sles11-sp1.ia64 sled11-sp1.x86 sle11-sp1-sdk.ia64 sled11-sp1.x86-64 sle11-sp1-sdk.s390x sles11-sp1.x86-64 sles11-sp1-vmware.x86 sles11-sp1.ppc SAT Patch Nr: 5479 |
| SLE 11 SP1 DEBUGINFO |
| Builds SAT Patch Nr: 6112 |
| SUSE Linux Enterprise Desktop 11 SP1 SUSE Linux Enterprise Desktop 11 SP2 SUSE Linux Enterprise Server 11 SP1 SUSE Linux Enterprise Server 11 SP1 for VMware |
| Builds SAT Patch Nr: 6112 |
| SLE 11 SP1 DEBUGINFO |
| Builds SAT Patch Nr: 6113 |
| SUSE Linux Enterprise Desktop 11 SP1 |
| Builds SAT Patch Nr: 6113 |
