Common Desktop Environment (CDE) is a commercial window management system for X. It is distributed with various commercial UNIX implementations. CDE does not check the validity of previously saved session. This vulnerability allows a local user to make modifications to the previously saved CDE session, and when the desktop restarts, give the user an xterm with elevated privileges. This could allow a local user to gain elevated privileges, including administrative access.
Common Desktop Environment (CDE) is a commercial window management system for X. It is distributed with various commercial UNIX implementations. CDE does not check the validity of previously saved session. This vulnerability allows a local user to make modifications to the previously saved CDE session, and when the desktop restarts, give the user an xterm with elevated privileges. This could allow a local user to gain elevated privileges, including administrative access.