CVE-2008-1142: Low severity aterm vulnerability
rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: it was later reported that rxvt-unicode, mrxvt, aterm, multi-aterm, and wterm are also affected. NOTE: realistic attack scenarios require that the victim enters a command on the wrong machine.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1142?
CVE-2008-1142 is classified as a medium severity vulnerability due to the potential for local users to hijack X11 connections.
How do I fix CVE-2008-1142?
To mitigate CVE-2008-1142, ensure that the DISPLAY environment variable is set properly or upgrade to a patched version of the affected terminal emulators.
Which software versions are affected by CVE-2008-1142?
CVE-2008-1142 affects several versions of aterm, Eterm, mrxvt, multi-aterm, rxvt, rxvt-unicode, and wterm.
What kind of attack can exploit CVE-2008-1142?
An attacker could exploit CVE-2008-1142 to gain unauthorized access to an X11 session by launching a terminal emulator on an unprotected display.
Is CVE-2008-1142 related to remote attacks?
CVE-2008-1142 primarily poses a risk for local users, as it exploits the absence of the DISPLAY environment variable rather than facilitating remote attacks.