Unrated severityNVD Advisory· Published Nov 3, 2006· Updated Apr 23, 2026
CVE-2006-5397
CVE-2006-5397
Description
The Xinput module (modules/im/ximcp/imLcIm.c) in X.Org libX11 1.0.2 and 1.0.3 opens a file for reading twice using the same file descriptor, which causes a file descriptor leak that allows local users to read files specified by the XCOMPOSEFILE environment variable via the duplicate file descriptor.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- bugs.freedesktop.org/show_bug.cginvdPatch
- secunia.com/advisories/22642nvdVendor Advisory
- gitweb.freedesktop.orgnvd
- secunia.com/advisories/22749nvd
- www.mandriva.com/security/advisoriesnvd
- www.securityfocus.com/bid/20845nvd
- www.vupen.com/english/advisories/2006/4289nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/29956nvd
News mentions
0No linked articles in our index yet.