Back to Database
Status published
High
CVE-2012-1093
The init script in the Debian x11-common package before 1:7.6+12...
Vulnerability Description
The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a privilege escalation during package installation.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-1093
Credits & Attribution
No credits recorded in the NVD database.
References
- https://security-tracker.debian.org/tracker/CVE-2012-1093
- https://access.redhat.com/security/cve/cve-2012-1093
- http://www.openwall.com/lists/oss-security/2012/03/01/1
- http://www.openwall.com/lists/oss-security/2012/02/29/1
- http://vladz.devzero.fr/012_x11-common-vuln.html
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E
More from Debian
View All →CVE-2025-8454
It was discovered that uscan, a tool to scan/watch upstream...
Unknown
0
CVE-2025-6297
dpkg-deb: Fix cleanup for control member with restricted directories
Unknown
0
CVE-2025-68462
Freedombox before 25.17.1 does not set proper permissions for the...
Low
3.2
CVE-2025-53391
The Debian zuluPolkit/CMakeLists.txt file for zuluCrypt through the zulucrypt_6.2.0-1 package...
Critical
9.3
CVE-2025-47153
Certain build processes for libuv and Node.js for 32-bit systems,...
Medium
6.5
Affected Vendor
Debian
View all reports →Affected Software
x11-common
Vulnerable Versions:
before 1:7.6+12
Timeline
Official Publish:
February 21st, 2020
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.