The Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060317, and Solaris 8 through 10 before 20061006, allows local users to overwrite arbitrary files, or read another user's Xsession errors file, via a symlink attack on a /tmp/xses-$USER file.
2006-10-10T04:06:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 2.6 (LOW)
AV:L/AC:H/Au:N/C:P/I:P/A:N
1.9
4.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | x.org | xdm | ≤ 1.0.3 | Yes |
| Operating System | netbsd | netbsd | ≤ current | Yes |
| Operating System | netbsd | netbsd | 1.0 | Yes |
| Operating System | netbsd | netbsd | 1.1 | Yes |
| Operating System | netbsd | netbsd | 1.2 | Yes |
| Operating System | netbsd | netbsd | 1.2.1 | Yes |
| Operating System | netbsd | netbsd | 1.3 | Yes |
| Operating System | netbsd | netbsd | 1.3.1 | Yes |
| Operating System | netbsd | netbsd | 1.3.2 | Yes |
| Operating System | netbsd | netbsd | 1.3.3 | Yes |
| Operating System | netbsd | netbsd | 1.4 | Yes |
| Operating System | netbsd | netbsd | 1.4 | Yes |
| Operating System | netbsd | netbsd | 1.4 | Yes |
| Operating System | netbsd | netbsd | 1.4 | Yes |
| Operating System | netbsd | netbsd | 1.4 | Yes |
| Operating System | netbsd | netbsd | 1.4.1 | Yes |
| Operating System | netbsd | netbsd | 1.4.1 | Yes |
| Operating System | netbsd | netbsd | 1.4.1 | Yes |
| Operating System | netbsd | netbsd | 1.4.1 | Yes |
| Operating System | netbsd | netbsd | 1.4.1 | Yes |
| Operating System | netbsd | netbsd | 1.4.1 | Yes |
| Operating System | netbsd | netbsd | 1.4.2 | Yes |
| Operating System | netbsd | netbsd | 1.4.2 | Yes |
| Operating System | netbsd | netbsd | 1.4.2 | Yes |
| Operating System | netbsd | netbsd | 1.4.2 | Yes |
| Operating System | netbsd | netbsd | 1.4.2 | Yes |
| Operating System | netbsd | netbsd | 1.4.3 | Yes |
| Operating System | netbsd | netbsd | 1.5 | Yes |
| Operating System | netbsd | netbsd | 1.5 | Yes |
| Operating System | netbsd | netbsd | 1.5 | Yes |
| Operating System | netbsd | netbsd | 1.5.1 | Yes |
| Operating System | netbsd | netbsd | 1.5.2 | Yes |
| Operating System | netbsd | netbsd | 1.5.3 | Yes |
| Operating System | netbsd | netbsd | 1.6 | Yes |
| Operating System | netbsd | netbsd | 1.6 | Yes |
| Operating System | netbsd | netbsd | 1.6.1 | Yes |
| Operating System | netbsd | netbsd | 1.6.2 | Yes |
| Operating System | netbsd | netbsd | 2.0 | Yes |
| Operating System | netbsd | netbsd | 2.0.1 | Yes |
| Operating System | netbsd | netbsd | 2.0.2 | Yes |
| Operating System | netbsd | netbsd | 2.0.3 | Yes |
| Operating System | netbsd | netbsd | 2.1 | Yes |
| Operating System | netbsd | netbsd | 3.0 | Yes |
| Operating System | netbsd | netbsd | 3.99.15 | Yes |
| Operating System | netbsd | netbsd | 4.0 | Yes |
| Operating System | sun | solaris | 8.0 | Yes |
| Operating System | sun | solaris | 8.0 | Yes |
| Operating System | sun | solaris | 8.0 | Yes |
| Operating System | sun | solaris | 9.0 | Yes |
| Operating System | sun | solaris | 9.0 | Yes |
| Operating System | sun | solaris | 9.0 | Yes |
| Operating System | sun | solaris | 10.0 | Yes |
| Operating System | sun | sunos | 5.8 | Yes |
| Operating System | sun | sunos | 5.9 | Yes |