First published: Mon Aug 27 2007(Updated: )
xterm, including 192-7.el4 in Red Hat Enterprise Linux and 208-3.1 in Debian GNU/Linux, sets the wrong group ownership of tty devices, which allows local users to write data to other users' terminals.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Enterprise Linux | ||
Xterm | =192-7.el4 | |
Debian | ||
Xterm | =208-3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2797 is considered a moderate severity vulnerability because it allows local users to interfere with other users' terminal sessions.
To fix CVE-2007-2797, ensure you update to the latest secure versions of xterm, specifically versions above 192-7.el4 and 208-3.1.
Local users on systems running vulnerable versions of xterm are affected by CVE-2007-2797.
Red Hat Enterprise Linux versions that include xterm 192-7.el4 and Debian systems with xterm 208-3.1 are known to be vulnerable to CVE-2007-2797.
No, CVE-2007-2797 is not a remote exploit; it requires local access to exploit the vulnerability.