Exploit:
Systems Affected: Ultrix systems with X11 libs
installed yet lacking a /dev/xcons.
Problem: /usr/lib/X11/xconsole can be used to
destructively overwrite any file on the system.
To duplicate set the display to a working server,
create a symbolic link from /tmp/Xconsole.log to
the file to be overwritten, and run xconsole. The
target file will be overwritten with a single line
error message concerning a nonexistant /dev/xcons.
Solution: The problem can be eliminated by creating
are root read-writeable touchfile as /dev/xcons.