CVE-2006-5397 Affecting libx11 package, versions [1.0.2,1.0.3]


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Not Defined
EPSS
0.04% (6th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-LIBX11-2371843
  • published26 Jan 2022
  • disclosed3 Nov 2006
  • creditUnknown

Introduced: 3 Nov 2006

CVE-2006-5397  (opens in a new tab)

How to fix?

There is no fixed version for libx11.

Overview

The Xinput module (modules/im/ximcp/imLcIm.c) in X.Org libX11 1.0.2 and 1.0.3 opens a file for reading twice using the same file descriptor, which causes a file descriptor leak that allows local users to read files specified by the XCOMPOSEFILE environment variable via the duplicate file descriptor.

References

CVSS Scores

version 3.1