CVE-2011-4613
EPSS 0.08%xorg - incorrect permission check
Published: 2/5/2014Modified: 4/28/2026
Also known as:DEBIAN-CVE-2011-4613
Description
The X.Org X wrapper (xserver-wrapper.c) in Debian GNU/Linux and Ubuntu Linux does not properly verify the TTY of a user who is starting X, which allows local users to bypass intended access restrictions by associating stdin with a file that is misinterpreted as the console TTY.
Affected packages (2)
- Debian/xorgfrom 0, < 1:7.6+10
- Debian/xorgfrom 0, < 1:7.5+8+squeeze1