CVE-2011-0465
x11-xserver-utils - missing input sanitizing
EPSS 5.8%
Description
xrdb.c in xrdb before 1.0.9 in X.Org X11R7.6 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a (1) DHCP or (2) XDMCP message.
How to fix CVE-2011-0465
To remediate CVE-2011-0465, upgrade the affected package to a fixed version below.
- Debian/x11-xserver-utils—upgrade to 7.6+2 or later
- Debian/x11-xserver-utils—upgrade to 7.5+3 or later
Is CVE-2011-0465 being exploited?
Moderate — EPSS is 5.8%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 7.6+2
- from 0, < 7.5+3