Eterm 0.9.4 opens a terminal window on :0 if -display is not specified and the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: realistic attack scenarios require that the victim enters a command on the wrong machine.
References
Configurations
Information
Published : 2008-04-07 11:44
Updated : 2009-02-25 22:51
NVD link : CVE-2008-1692
Mitre link : CVE-2008-1692
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
eterm
- eterm