Lucene search

K
cveMitreCVE-2008-1142
HistoryApr 07, 2008 - 5:44 p.m.

CVE-2008-1142

2008-04-0717:44:00
CWE-264
mitre
web.nvd.nist.gov
33
rxvt
terminal window
hijack
x11
security
local users
cve-2008-1142

CVSS2

3.7

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:H/Au:N/C:P/I:P/A:P

AI Score

8.3

Confidence

High

EPSS

0

Percentile

10.1%

rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: it was later reported that rxvt-unicode, mrxvt, aterm, multi-aterm, and wterm are also affected. NOTE: realistic attack scenarios require that the victim enters a command on the wrong machine.

Affected configurations

Nvd
Node
atermatermRange1.0.0
OR
atermatermMatch0.1.0
OR
atermatermMatch0.1.1
OR
atermatermMatch0.2.0
OR
atermatermMatch0.3.0
OR
atermatermMatch0.3.1
OR
atermatermMatch0.3.2
OR
atermatermMatch0.3.3
OR
atermatermMatch0.3.4
OR
atermatermMatch0.3.5
OR
atermatermMatch0.3.6
OR
atermatermMatch0.4.0
OR
atermatermMatch0.4.1
OR
atermatermMatch0.4.2
OR
atermatermMatch1.00beta1
OR
atermatermMatch1.00beta2
OR
atermatermMatch1.00beta3
OR
atermatermMatch1.00beta4
OR
etermetermRange0.9.3
OR
etermetermMatch0.9.2
OR
mrxvtmrxvtRange0.5.2
OR
mrxvtmrxvtMatch0.4.2
OR
multi-atermmulti-atermRange0.2
OR
multi-atermmulti-atermMatch0.0.1
OR
multi-atermmulti-atermMatch0.0.3
OR
multi-atermmulti-atermMatch0.0.4
OR
multi-atermmulti-atermMatch0.0.5
OR
multi-atermmulti-atermMatch0.1
OR
rxvtrxvtRange2.7.9
OR
rxvtrxvtMatch2.6.1
OR
rxvtrxvtMatch2.6.2
OR
rxvtrxvtMatch2.6.3
OR
rxvtrxvtMatch2.6.4
OR
rxvtrxvtMatch2.7.5
OR
rxvtrxvtMatch2.7.6
OR
rxvtrxvtMatch2.7.7
OR
rxvtrxvtMatch2.7.8
OR
rxvt-unicoderxvt-unicodeRange9.01
OR
rxvt-unicoderxvt-unicodeMatch1.0
OR
rxvt-unicoderxvt-unicodeMatch1.1
OR
rxvt-unicoderxvt-unicodeMatch1.2
OR
rxvt-unicoderxvt-unicodeMatch1.3
OR
rxvt-unicoderxvt-unicodeMatch1.4
OR
rxvt-unicoderxvt-unicodeMatch1.5
OR
rxvt-unicoderxvt-unicodeMatch1.6
OR
rxvt-unicoderxvt-unicodeMatch1.7
OR
rxvt-unicoderxvt-unicodeMatch1.8
OR
rxvt-unicoderxvt-unicodeMatch1.9
OR
rxvt-unicoderxvt-unicodeMatch1.91
OR
rxvt-unicoderxvt-unicodeMatch2.0
OR
rxvt-unicoderxvt-unicodeMatch2.1
OR
rxvt-unicoderxvt-unicodeMatch2.2
OR
rxvt-unicoderxvt-unicodeMatch2.3
OR
rxvt-unicoderxvt-unicodeMatch2.4
OR
rxvt-unicoderxvt-unicodeMatch2.5
OR
rxvt-unicoderxvt-unicodeMatch2.6
OR
rxvt-unicoderxvt-unicodeMatch2.7
OR
rxvt-unicoderxvt-unicodeMatch2.8
OR
rxvt-unicoderxvt-unicodeMatch2.9
OR
rxvt-unicoderxvt-unicodeMatch3.0
OR
rxvt-unicoderxvt-unicodeMatch3.1
OR
rxvt-unicoderxvt-unicodeMatch3.2
OR
rxvt-unicoderxvt-unicodeMatch3.3
OR
rxvt-unicoderxvt-unicodeMatch3.4
OR
rxvt-unicoderxvt-unicodeMatch3.5
OR
rxvt-unicoderxvt-unicodeMatch3.6
OR
rxvt-unicoderxvt-unicodeMatch3.7
OR
rxvt-unicoderxvt-unicodeMatch3.8
OR
rxvt-unicoderxvt-unicodeMatch3.9
OR
rxvt-unicoderxvt-unicodeMatch4.0
OR
rxvt-unicoderxvt-unicodeMatch4.1
OR
rxvt-unicoderxvt-unicodeMatch4.2
OR
rxvt-unicoderxvt-unicodeMatch4.3
OR
rxvt-unicoderxvt-unicodeMatch4.4
OR
rxvt-unicoderxvt-unicodeMatch4.5
OR
rxvt-unicoderxvt-unicodeMatch4.6
OR
rxvt-unicoderxvt-unicodeMatch4.7
OR
rxvt-unicoderxvt-unicodeMatch4.8
OR
rxvt-unicoderxvt-unicodeMatch4.9
OR
rxvt-unicoderxvt-unicodeMatch5.0
OR
rxvt-unicoderxvt-unicodeMatch5.1
OR
rxvt-unicoderxvt-unicodeMatch5.2
OR
rxvt-unicoderxvt-unicodeMatch5.3
OR
rxvt-unicoderxvt-unicodeMatch5.4
OR
rxvt-unicoderxvt-unicodeMatch5.5
OR
rxvt-unicoderxvt-unicodeMatch5.6
OR
rxvt-unicoderxvt-unicodeMatch5.7
OR
rxvt-unicoderxvt-unicodeMatch5.8
OR
rxvt-unicoderxvt-unicodeMatch5.9
OR
rxvt-unicoderxvt-unicodeMatch6.0
OR
rxvt-unicoderxvt-unicodeMatch6.1
OR
rxvt-unicoderxvt-unicodeMatch6.2
OR
rxvt-unicoderxvt-unicodeMatch6.3
OR
rxvt-unicoderxvt-unicodeMatch7.0
OR
rxvt-unicoderxvt-unicodeMatch7.1
OR
rxvt-unicoderxvt-unicodeMatch7.2
OR
rxvt-unicoderxvt-unicodeMatch7.3
OR
rxvt-unicoderxvt-unicodeMatch7.4
OR
rxvt-unicoderxvt-unicodeMatch7.5
OR
rxvt-unicoderxvt-unicodeMatch7.6
OR
rxvt-unicoderxvt-unicodeMatch7.7
OR
rxvt-unicoderxvt-unicodeMatch7.8
OR
rxvt-unicoderxvt-unicodeMatch7.9
OR
rxvt-unicoderxvt-unicodeMatch8.0
OR
rxvt-unicoderxvt-unicodeMatch8.1
OR
rxvt-unicoderxvt-unicodeMatch8.2
OR
rxvt-unicoderxvt-unicodeMatch8.3
OR
rxvt-unicoderxvt-unicodeMatch8.4
OR
rxvt-unicoderxvt-unicodeMatch8.5
OR
rxvt-unicoderxvt-unicodeMatch8.5a
OR
rxvt-unicoderxvt-unicodeMatch8.6
OR
rxvt-unicoderxvt-unicodeMatch8.7
OR
rxvt-unicoderxvt-unicodeMatch8.8
OR
rxvt-unicoderxvt-unicodeMatch8.9
OR
rxvt-unicoderxvt-unicodeMatch9.0
OR
wtermwtermRange6.2.8a2
OR
wtermwtermMatch6.2.5
OR
wtermwtermMatch6.2.6
VendorProductVersionCPE
atermaterm*cpe:2.3:a:aterm:aterm:*:*:*:*:*:*:*:*
atermaterm0.1.0cpe:2.3:a:aterm:aterm:0.1.0:*:*:*:*:*:*:*
atermaterm0.1.1cpe:2.3:a:aterm:aterm:0.1.1:*:*:*:*:*:*:*
atermaterm0.2.0cpe:2.3:a:aterm:aterm:0.2.0:*:*:*:*:*:*:*
atermaterm0.3.0cpe:2.3:a:aterm:aterm:0.3.0:*:*:*:*:*:*:*
atermaterm0.3.1cpe:2.3:a:aterm:aterm:0.3.1:*:*:*:*:*:*:*
atermaterm0.3.2cpe:2.3:a:aterm:aterm:0.3.2:*:*:*:*:*:*:*
atermaterm0.3.3cpe:2.3:a:aterm:aterm:0.3.3:*:*:*:*:*:*:*
atermaterm0.3.4cpe:2.3:a:aterm:aterm:0.3.4:*:*:*:*:*:*:*
atermaterm0.3.5cpe:2.3:a:aterm:aterm:0.3.5:*:*:*:*:*:*:*
Rows per page:
1-10 of 1181

CVSS2

3.7

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:H/Au:N/C:P/I:P/A:P

AI Score

8.3

Confidence

High

EPSS

0

Percentile

10.1%