Vulnerabilities > CVE-2006-4124 - Local Arbitrary File Creation vulnerability in Lesstif 0.93.94

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
lesstif
exploit available

Summary

The libXm library in LessTif 0.95.0 and earlier allows local users to gain privileges via the DEBUG_FILE environment variable, which is used to create world-writable files when libXm is run from a setuid program.

Vulnerable Configurations

Part Description Count
Application
Lesstif
2

Exploit-Db

idEDB-ID:2144

Statements

contributorMark J Cox
lastmodified2006-08-16
organizationRed Hat
statementLessTif is shipped with Red Hat Enterprise Linux 2.1 but not 3 or 4. On Enterprise Linux 2.1 we build LessTif with debugging disabled, so the DEBUG_FILE environment variable is ignored and this issue cannot be exploited.