Skip to main content

Xorg Critical Security Flaw Silently Patched

posted onAugust 18, 2010
by hitbsecnews

On June 17th, the X.org team was notified by Invisible Things Lab of a critical security flaw that affected both x86_32 and x86_64 platforms. The flaw deals with escalated privileges of a user process that has access to the X server.

The founder of ITL said of the flaw, 'The attack allows a (unpriviliged) user process that has access to the X server (so, any GUI application) to unconditionally escalate to root (but again, it doesn't take advantage of any bug in the X server!). In other words: any GUI application (think e.g. sandboxed PDF viewer), if compromised (e.g. via malicious PDF document) can bypass all the Linux fancy security mechanisms, and escalate to root, and compromise the whole system.'

Source

Tags

Linux

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th