Junglewise Threat Intelligence

CVE-1999-0965: X.Org xterm race condition in logging option

CVE-1999-0965 · Severity: medium · CVSS 6.2 · Published 1997-09-19

Vendors: X.Org.

Executive brief

A vulnerability exists in xterm, a standard terminal emulator for the X Window System. A local user can exploit a timing flaw in the terminal's logging feature to modify sensitive system files they should not have access to. This could allow an attacker to corrupt data or gain elevated privileges on the affected system.

Technical details

A race condition exists in the logging functionality of xterm. By exploiting a time-of-check to time-of-use (TOCTOU) window when the logging option is enabled, a local attacker can redirect the log output to arbitrary files. Because xterm often runs with elevated privileges (such as setuid root) to manage terminal devices, this flaw allows the modification of system-critical files. The vulnerability affects X.Org xterm and X11R5 through fix-25. Successful exploitation requires local access and precise timing to manipulate file descriptors or symbolic links during the logging initialization process.

Affected products

  • X.Org xterm
  • X.Org X11R5 up to fix-25

Timeline

  • 1997-09-19: disclosed
  • 1997-09-19: advisory

References