CVE-2006-5214

Race condition in the Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060225, and Solaris 8 through 10 before 20061006, causes a user’s Xsession errors file to have weak permissions before a chmod is performed, which allows local users to read Xsession errors files of other users.

Date published : 2006-10-09

http://www.securityfocus.com/bid/20400

http://support.avaya.com/elmodocs2/security/ASA-2006-250.htm