CVE-2011-0465

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
08/04/2011
Last modified:
11/04/2025

Description

xrdb.c in xrdb before 1.0.9 in X.Org X11R7.6 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a (1) DHCP or (2) XDMCP message.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:matthias_hopf:xrdb:*:*:*:*:*:*:*:* 1.0.8 (including)
cpe:2.3:a:matthias_hopf:xrdb:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:matthias_hopf:xrdb:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:matthias_hopf:xrdb:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:matthias_hopf:xrdb:1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:matthias_hopf:xrdb:1.0.6:*:*:*:*:*:*:*
cpe:2.3:a:matthias_hopf:xrdb:1.0.7:*:*:*:*:*:*:*
cpe:2.3:a:x:x11:*:*:*:*:*:*:*:* r7.6 (including)
cpe:2.3:a:x:x11:r1:*:*:*:*:*:*:*
cpe:2.3:a:x:x11:r2:*:*:*:*:*:*:*
cpe:2.3:a:x:x11:r3:*:*:*:*:*:*:*
cpe:2.3:a:x:x11:r4:*:*:*:*:*:*:*
cpe:2.3:a:x:x11:r5:*:*:*:*:*:*:*
cpe:2.3:a:x:x11:r6:*:*:*:*:*:*:*
cpe:2.3:a:x:x11:r6.1:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools