Back

CVE-2002-1472

Untrusted search path vulnerability in libX11.so in xfree86, when used in setuid or setgid programs, allows local users to gain root privileges via a modified LD_PRELOAD environment variable that points to a malicious module.

Published: Mar 3, 2003 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
xfree86_project x11r6 4.1.0
xfree86_project x11r6 4.2.0

GitHub Security Advisory GHSA-ch45-xvph-66gf

Untrusted search path vulnerability in libX11.so in xfree86, when used in setuid or setgid...

Risk Scores

CVSS Score 7.2 / 10
EPSS Score 0.37%

Top 70% most likely to be exploited

Threat Score 28.9 / 100

Data Sources

NVD EPSS GitHub