UBUNTU-CVE-2012-1093

Source
https://ubuntu.com/security/CVE-2012-1093
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2012/UBUNTU-CVE-2012-1093.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2012-1093
Upstream
Withdrawn
2025-07-18T16:42:45Z
Published
2020-02-21T19:15:00Z
Modified
2025-07-16T07:30:53.119198Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • Ubuntu - low
Summary
[none]
Details

The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a privilege escalation during package installation.

References

Affected packages

Ubuntu:16.04:LTS / xorg

Package

Name
xorg
Purl
pkg:deb/ubuntu/xorg@1:7.7+12ubuntu1?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:7.7+12ubuntu1

Affected versions

1:7.*
1:7.7+7ubuntu4

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "x11-common",
            "binary_version": "1:7.7+12ubuntu1"
        },
        {
            "binary_name": "xbase-clients",
            "binary_version": "1:7.7+12ubuntu1"
        },
        {
            "binary_name": "xorg",
            "binary_version": "1:7.7+12ubuntu1"
        },
        {
            "binary_name": "xorg-dev",
            "binary_version": "1:7.7+12ubuntu1"
        },
        {
            "binary_name": "xserver-xorg",
            "binary_version": "1:7.7+12ubuntu1"
        },
        {
            "binary_name": "xserver-xorg-input-all",
            "binary_version": "1:7.7+12ubuntu1"
        },
        {
            "binary_name": "xserver-xorg-video-all",
            "binary_version": "1:7.7+12ubuntu1"
        },
        {
            "binary_name": "xutils",
            "binary_version": "1:7.7+12ubuntu1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2012/UBUNTU-CVE-2012-1093.json"

Ubuntu:18.04:LTS / xorg

Package

Name
xorg
Purl
pkg:deb/ubuntu/xorg@1:7.7+19ubuntu7?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:7.7+19ubuntu7

Affected versions

1:7.*
1:7.7+19ubuntu3
1:7.7+19ubuntu4
1:7.7+19ubuntu5
1:7.7+19ubuntu6

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "x11-common",
            "binary_version": "1:7.7+19ubuntu7"
        },
        {
            "binary_name": "xbase-clients",
            "binary_version": "1:7.7+19ubuntu7"
        },
        {
            "binary_name": "xorg",
            "binary_version": "1:7.7+19ubuntu7"
        },
        {
            "binary_name": "xorg-dev",
            "binary_version": "1:7.7+19ubuntu7"
        },
        {
            "binary_name": "xserver-xorg",
            "binary_version": "1:7.7+19ubuntu7"
        },
        {
            "binary_name": "xserver-xorg-input-all",
            "binary_version": "1:7.7+19ubuntu7"
        },
        {
            "binary_name": "xserver-xorg-video-all",
            "binary_version": "1:7.7+19ubuntu7"
        },
        {
            "binary_name": "xutils",
            "binary_version": "1:7.7+19ubuntu7"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2012/UBUNTU-CVE-2012-1093.json"