PT-2008-1126 · Aterm+1 · Aterm+1

Bernhard R. Link

·

Publicado

2008-04-07

·

Atualizado

2009-02-26

·

CVE-2008-1692

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Eterm version 0.9.4 aterm versions prior to 1.0.1-r1
Description The issue allows local users to potentially hijack X11 connections under specific conditions, such as when the DISPLAY environment variable is not set and the -display option is not specified. Realistic attack scenarios require the victim to enter a command on the wrong machine. Multiple vulnerabilities in the aterm package can lead to breaches of confidentiality, integrity, and availability of protected information, with exploitation possible locally.
Recommendations For Eterm version 0.9.4, consider setting the DISPLAY environment variable or specifying the -display option to prevent unauthorized access. For aterm versions prior to 1.0.1-r1, update to version 1.0.1-r1 or later to resolve the vulnerabilities. As a temporary workaround, consider restricting access to the terminal window to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09630
CVE-2008-1692

Produtos afetados

Eterm
Aterm