Attachmate Reflection X X.Org xrdb Hostname Command

by Carol~ Moderator - 4/16/12 8:10 AM

In Reply to: VULNERABILITIES / FIXES - April 16, 2012 by Carol~ Moderator

Attachmate Reflection X X.Org xrdb Hostname Command Injection Security Issue

Release Date : 2012-04-16

Criticality level : Less critical
Impact : Privilege escalation
System access
Where : From local network
Solution Status : Vendor Patch

Software: Reflection 14.x
Reflection X 2011

Description:
Attachmate has acknowledged a security issue in Reflection X, which can be exploited by malicious, local users to gain escalated privileges or by malicious people to compromise a vulnerable system.

The security issue is reported in versions prior to 14.1 SP2.

Solution:
Update to version 14.1 SP2.

Original Advisory:
http://support.attachmate.com/techdocs/1708.html

http://secunia.com/advisories/48865/