CVE-2006-5397 describes a file descriptor leak vulnerability in the Xinput module of X.Org libX11 versions 1.0.2 and 1.0.3. This flaw allows a local attacker to read arbitrary files by manipulating the XCOMPOSEFILE environment variable due to the module opening a file twice with the same file descriptor. With a CVSS score of 2.1, this is a low-severity vulnerability, requiring local access and resulting only in information disclosure (confidentiality impact). There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.2CPE matchmatch criteria | cpe:2.3:a:x.org:libx11:1.0.2:*:*:*:*:*:*:* | ||
1.0.3CPE matchmatch criteria | cpe:2.3:a:x.org:libx11:1.0.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.