CVE Database
/

CVE-2006-5397

Back to search

CVE-2006-5397

Published: Nov 3, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

The Xinput module (modules/im/ximcp/imLcIm.c) in X.Org libX11 1.0.2 and 1.0.3 opens a file for reading twice using the same file descriptor, which causes a file descriptor leak that allows local users to read files specified by the XCOMPOSEFILE environment variable via the duplicate file descriptor.

VendorProductVersions

n/a

n/a

affected
n/a

References

22749
third-party-advisory
x_refsource_SECUNIA
20845
vdb-entry
x_refsource_BID
ADV-2006-4289
vdb-entry
x_refsource_VUPEN
22642
third-party-advisory
x_refsource_SECUNIA
MDKSA-2006:199
vendor-advisory
x_refsource_MANDRIVA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now