The GUI installation for iCal 2.1 Patch 2 disables access control for the X server using an "xhost +" command, which allows remote attackers to monitor X Windows events and gain privileges.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/5752 | vdb entry |
http://www.atstake.com/research/advisories/2000/a100900-1.txt | exploit patch vendor advisory |
http://www.securityfocus.com/bid/1767 | vdb entry |
http://www.osvdb.org/7213 | vdb entry |