CVE Vulnerabilities

CVE-2008-1142

Published: Apr 07, 2008 | Modified: Feb 26, 2009
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.7 LOW
AV:L/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: it was later reported that rxvt-unicode, mrxvt, aterm, multi-aterm, and wterm are also affected. NOTE: realistic attack scenarios require that the victim enters a command on the wrong machine.

Affected Software

Name Vendor Start Version End Version
Aterm Aterm * 1.0.0 (including)
Aterm Aterm 0.1.0 (including) 0.1.0 (including)
Aterm Aterm 0.1.1 (including) 0.1.1 (including)
Aterm Aterm 0.2.0 (including) 0.2.0 (including)
Aterm Aterm 0.3.0 (including) 0.3.0 (including)
Aterm Aterm 0.3.1 (including) 0.3.1 (including)
Aterm Aterm 0.3.2 (including) 0.3.2 (including)
Aterm Aterm 0.3.3 (including) 0.3.3 (including)
Aterm Aterm 0.3.4 (including) 0.3.4 (including)
Aterm Aterm 0.3.5 (including) 0.3.5 (including)
Aterm Aterm 0.3.6 (including) 0.3.6 (including)
Aterm Aterm 0.4.0 (including) 0.4.0 (including)
Aterm Aterm 0.4.1 (including) 0.4.1 (including)
Aterm Aterm 0.4.2 (including) 0.4.2 (including)
Aterm Aterm 1.00-beta1 (including) 1.00-beta1 (including)
Aterm Aterm 1.00-beta2 (including) 1.00-beta2 (including)
Aterm Aterm 1.00-beta3 (including) 1.00-beta3 (including)
Aterm Aterm 1.00-beta4 (including) 1.00-beta4 (including)
Eterm Eterm * 0.9.3 (including)
Eterm Eterm 0.9.2 (including) 0.9.2 (including)
Mrxvt Mrxvt * 0.5.2 (including)
Mrxvt Mrxvt 0.4.2 (including) 0.4.2 (including)
Multi-aterm Multi-aterm * 0.2 (including)
Multi-aterm Multi-aterm 0.0.1 (including) 0.0.1 (including)
Multi-aterm Multi-aterm 0.0.3 (including) 0.0.3 (including)
Multi-aterm Multi-aterm 0.0.4 (including) 0.0.4 (including)
Multi-aterm Multi-aterm 0.0.5 (including) 0.0.5 (including)
Multi-aterm Multi-aterm 0.1 (including) 0.1 (including)
Rxvt Rxvt * 2.7.9 (including)
Rxvt Rxvt 2.6.1 (including) 2.6.1 (including)
Rxvt Rxvt 2.6.2 (including) 2.6.2 (including)
Rxvt Rxvt 2.6.3 (including) 2.6.3 (including)
Rxvt Rxvt 2.6.4 (including) 2.6.4 (including)
Rxvt Rxvt 2.7.5 (including) 2.7.5 (including)
Rxvt Rxvt 2.7.6 (including) 2.7.6 (including)
Rxvt Rxvt 2.7.7 (including) 2.7.7 (including)
Rxvt Rxvt 2.7.8 (including) 2.7.8 (including)
Rxvt-unicode Rxvt-unicode * 9.01 (including)
Rxvt-unicode Rxvt-unicode 1.0 (including) 1.0 (including)
Rxvt-unicode Rxvt-unicode 1.1 (including) 1.1 (including)
Rxvt-unicode Rxvt-unicode 1.2 (including) 1.2 (including)
Rxvt-unicode Rxvt-unicode 1.3 (including) 1.3 (including)
Rxvt-unicode Rxvt-unicode 1.4 (including) 1.4 (including)
Rxvt-unicode Rxvt-unicode 1.5 (including) 1.5 (including)
Rxvt-unicode Rxvt-unicode 1.6 (including) 1.6 (including)
Rxvt-unicode Rxvt-unicode 1.7 (including) 1.7 (including)
Rxvt-unicode Rxvt-unicode 1.8 (including) 1.8 (including)
Rxvt-unicode Rxvt-unicode 1.9 (including) 1.9 (including)
Rxvt-unicode Rxvt-unicode 1.91 (including) 1.91 (including)
Rxvt-unicode Rxvt-unicode 2.0 (including) 2.0 (including)
Rxvt-unicode Rxvt-unicode 2.1 (including) 2.1 (including)
Rxvt-unicode Rxvt-unicode 2.2 (including) 2.2 (including)
Rxvt-unicode Rxvt-unicode 2.3 (including) 2.3 (including)
Rxvt-unicode Rxvt-unicode 2.4 (including) 2.4 (including)
Rxvt-unicode Rxvt-unicode 2.5 (including) 2.5 (including)
Rxvt-unicode Rxvt-unicode 2.6 (including) 2.6 (including)
Rxvt-unicode Rxvt-unicode 2.7 (including) 2.7 (including)
Rxvt-unicode Rxvt-unicode 2.8 (including) 2.8 (including)
Rxvt-unicode Rxvt-unicode 2.9 (including) 2.9 (including)
Rxvt-unicode Rxvt-unicode 3.0 (including) 3.0 (including)
Rxvt-unicode Rxvt-unicode 3.1 (including) 3.1 (including)
Rxvt-unicode Rxvt-unicode 3.2 (including) 3.2 (including)
Rxvt-unicode Rxvt-unicode 3.3 (including) 3.3 (including)
Rxvt-unicode Rxvt-unicode 3.4 (including) 3.4 (including)
Rxvt-unicode Rxvt-unicode 3.5 (including) 3.5 (including)
Rxvt-unicode Rxvt-unicode 3.6 (including) 3.6 (including)
Rxvt-unicode Rxvt-unicode 3.7 (including) 3.7 (including)
Rxvt-unicode Rxvt-unicode 3.8 (including) 3.8 (including)
Rxvt-unicode Rxvt-unicode 3.9 (including) 3.9 (including)
Rxvt-unicode Rxvt-unicode 4.0 (including) 4.0 (including)
Rxvt-unicode Rxvt-unicode 4.1 (including) 4.1 (including)
Rxvt-unicode Rxvt-unicode 4.2 (including) 4.2 (including)
Rxvt-unicode Rxvt-unicode 4.3 (including) 4.3 (including)
Rxvt-unicode Rxvt-unicode 4.4 (including) 4.4 (including)
Rxvt-unicode Rxvt-unicode 4.5 (including) 4.5 (including)
Rxvt-unicode Rxvt-unicode 4.6 (including) 4.6 (including)
Rxvt-unicode Rxvt-unicode 4.7 (including) 4.7 (including)
Rxvt-unicode Rxvt-unicode 4.8 (including) 4.8 (including)
Rxvt-unicode Rxvt-unicode 4.9 (including) 4.9 (including)
Rxvt-unicode Rxvt-unicode 5.0 (including) 5.0 (including)
Rxvt-unicode Rxvt-unicode 5.1 (including) 5.1 (including)
Rxvt-unicode Rxvt-unicode 5.2 (including) 5.2 (including)
Rxvt-unicode Rxvt-unicode 5.3 (including) 5.3 (including)
Rxvt-unicode Rxvt-unicode 5.4 (including) 5.4 (including)
Rxvt-unicode Rxvt-unicode 5.5 (including) 5.5 (including)
Rxvt-unicode Rxvt-unicode 5.6 (including) 5.6 (including)
Rxvt-unicode Rxvt-unicode 5.7 (including) 5.7 (including)
Rxvt-unicode Rxvt-unicode 5.8 (including) 5.8 (including)
Rxvt-unicode Rxvt-unicode 5.9 (including) 5.9 (including)
Rxvt-unicode Rxvt-unicode 6.0 (including) 6.0 (including)
Rxvt-unicode Rxvt-unicode 6.1 (including) 6.1 (including)
Rxvt-unicode Rxvt-unicode 6.2 (including) 6.2 (including)
Rxvt-unicode Rxvt-unicode 6.3 (including) 6.3 (including)
Rxvt-unicode Rxvt-unicode 7.0 (including) 7.0 (including)
Rxvt-unicode Rxvt-unicode 7.1 (including) 7.1 (including)
Rxvt-unicode Rxvt-unicode 7.2 (including) 7.2 (including)
Rxvt-unicode Rxvt-unicode 7.3 (including) 7.3 (including)
Rxvt-unicode Rxvt-unicode 7.4 (including) 7.4 (including)
Rxvt-unicode Rxvt-unicode 7.5 (including) 7.5 (including)
Rxvt-unicode Rxvt-unicode 7.6 (including) 7.6 (including)
Rxvt-unicode Rxvt-unicode 7.7 (including) 7.7 (including)
Rxvt-unicode Rxvt-unicode 7.8 (including) 7.8 (including)
Rxvt-unicode Rxvt-unicode 7.9 (including) 7.9 (including)
Rxvt-unicode Rxvt-unicode 8.0 (including) 8.0 (including)
Rxvt-unicode Rxvt-unicode 8.1 (including) 8.1 (including)
Rxvt-unicode Rxvt-unicode 8.2 (including) 8.2 (including)
Rxvt-unicode Rxvt-unicode 8.3 (including) 8.3 (including)
Rxvt-unicode Rxvt-unicode 8.4 (including) 8.4 (including)
Rxvt-unicode Rxvt-unicode 8.5 (including) 8.5 (including)
Rxvt-unicode Rxvt-unicode 8.5a (including) 8.5a (including)
Rxvt-unicode Rxvt-unicode 8.6 (including) 8.6 (including)
Rxvt-unicode Rxvt-unicode 8.7 (including) 8.7 (including)
Rxvt-unicode Rxvt-unicode 8.8 (including) 8.8 (including)
Rxvt-unicode Rxvt-unicode 8.9 (including) 8.9 (including)
Rxvt-unicode Rxvt-unicode 9.0 (including) 9.0 (including)
Wterm Wterm * 6.2.8a2 (including)
Wterm Wterm 6.2.5 (including) 6.2.5 (including)
Wterm Wterm 6.2.6 (including) 6.2.6 (including)
Rxvt Ubuntu dapper *
Rxvt Ubuntu edgy *
Rxvt Ubuntu feisty *
Rxvt Ubuntu gutsy *
Rxvt Ubuntu hardy *
Rxvt Ubuntu upstream *

References