6.9
CVSSv2

CVE-2008-1692

Published: 07/04/2008 Updated: 26/02/2009
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Eterm 0.9.4 opens a terminal window on :0 if -display is not specified and the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: realistic attack scenarios require that the victim enters a command on the wrong machine.

Vulnerable Product Search on Vulmon Subscribe to Product

eterm eterm 0.9.4

Vendor Advisories

Debian Bug report logs - #473127 eterm: opens window on unspecified display Package: eterm; Maintainer for eterm is José Antonio Jiménez Madrid <donjosemadrid@gmailcom>; Source for eterm is src:eterm (PTS, buildd, popcon) Reported by: "Bernhard R Link" <brlink@debianorg> Date: Fri, 28 Mar 2008 14:03:01 UTC Seve ...