PT-2008-1126 · Aterm+1 · Aterm+1
Bernhard R. Link
·
Published
2008-04-07
·
Updated
2009-02-26
·
CVE-2008-1692
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Eterm version 0.9.4
aterm versions prior to 1.0.1-r1
Description
The issue allows local users to potentially hijack X11 connections under specific conditions, such as when the DISPLAY environment variable is not set and the -display option is not specified. Realistic attack scenarios require the victim to enter a command on the wrong machine. Multiple vulnerabilities in the aterm package can lead to breaches of confidentiality, integrity, and availability of protected information, with exploitation possible locally.
Recommendations
For Eterm version 0.9.4, consider setting the DISPLAY environment variable or specifying the -display option to prevent unauthorized access.
For aterm versions prior to 1.0.1-r1, update to version 1.0.1-r1 or later to resolve the vulnerabilities.
As a temporary workaround, consider restricting access to the terminal window to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eterm
Aterm