The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a privilege escalation during package installation.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "x11-common",
"binary_version": "1:7.7+12ubuntu1"
},
{
"binary_name": "xbase-clients",
"binary_version": "1:7.7+12ubuntu1"
},
{
"binary_name": "xorg",
"binary_version": "1:7.7+12ubuntu1"
},
{
"binary_name": "xorg-dev",
"binary_version": "1:7.7+12ubuntu1"
},
{
"binary_name": "xserver-xorg",
"binary_version": "1:7.7+12ubuntu1"
},
{
"binary_name": "xserver-xorg-input-all",
"binary_version": "1:7.7+12ubuntu1"
},
{
"binary_name": "xserver-xorg-video-all",
"binary_version": "1:7.7+12ubuntu1"
},
{
"binary_name": "xutils",
"binary_version": "1:7.7+12ubuntu1"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "x11-common",
"binary_version": "1:7.7+19ubuntu7"
},
{
"binary_name": "xbase-clients",
"binary_version": "1:7.7+19ubuntu7"
},
{
"binary_name": "xorg",
"binary_version": "1:7.7+19ubuntu7"
},
{
"binary_name": "xorg-dev",
"binary_version": "1:7.7+19ubuntu7"
},
{
"binary_name": "xserver-xorg",
"binary_version": "1:7.7+19ubuntu7"
},
{
"binary_name": "xserver-xorg-input-all",
"binary_version": "1:7.7+19ubuntu7"
},
{
"binary_name": "xserver-xorg-video-all",
"binary_version": "1:7.7+19ubuntu7"
},
{
"binary_name": "xutils",
"binary_version": "1:7.7+19ubuntu7"
}
]
}