CVE-2011-4029 describes a symlink attack vulnerability in the LockServer function of X.Org xserver versions prior to 1.11.2. This flaw allows a local attacker to manipulate temporary lock files, changing arbitrary file permissions to 444, enabling unauthorized reading, and potentially causing a denial of service by removing execution permissions. The vulnerability has a low CVSS score of 1.9 (AV:L/AC:M/Au:N/C:P/I:N/A:N), indicating local access and medium attack complexity are required, with potential for partial confidentiality impact. While not listed on the KEV catalog and showing no active exploitation, a public exploit (EDB-18040) exists, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.11.1CPE matchmatch criteria | cpe:2.3:a:x.org:x_server:*:*:*:*:*:*:*:* | ||
1.11.0CPE matchmatch criteria | cpe:2.3:a:x.org:x_server:1.11.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.