Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-1142

Опубликовано: 07 апр. 2008
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 3.7

Описание

rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: it was later reported that rxvt-unicode, mrxvt, aterm, multi-aterm, and wterm are also affected. NOTE: realistic attack scenarios require that the victim enters a command on the wrong machine.

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

1:2.6.4-14
edgy

ignored

end of life, was needed
feisty

ignored

end of life, was needed
gutsy

ignored

end of life, was needed
hardy

ignored

end of life
intrepid

not-affected

1:2.6.4-14
jaunty

not-affected

1:2.6.4-14
karmic

not-affected

1:2.6.4-14
lucid

not-affected

1:2.6.4-14

Показывать по

Ссылки на источники

EPSS

Процентиль: 20%
0.00064
Низкий

3.7 Low

CVSS2

Связанные уязвимости

redhat
больше 17 лет назад

rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: it was later reported that rxvt-unicode, mrxvt, aterm, multi-aterm, and wterm are also affected. NOTE: realistic attack scenarios require that the victim enters a command on the wrong machine.

nvd
больше 17 лет назад

rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: it was later reported that rxvt-unicode, mrxvt, aterm, multi-aterm, and wterm are also affected. NOTE: realistic attack scenarios require that the victim enters a command on the wrong machine.

debian
больше 17 лет назад

rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment va ...

github
больше 3 лет назад

rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: it was later reported that rxvt-unicode, mrxvt, aterm, multi-aterm, and wterm are also affected. NOTE: realistic attack scenarios require that the victim enters a command on the wrong machine.

suse-cvrf
больше 2 лет назад

Security update for rxvt-unicode

EPSS

Процентиль: 20%
0.00064
Низкий

3.7 Low

CVSS2