CVE-2008-1692: Medium severity eterm vulnerability
Eterm 0.9.4 opens a terminal window on :0 if -display is not specified and the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: realistic attack scenarios require that the victim enters a command on the wrong machine.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1692?
CVE-2008-1692 has a medium severity level due to potential local user exploitation.
How do I fix CVE-2008-1692?
To fix CVE-2008-1692, ensure that the DISPLAY environment variable is set correctly or specify the -display parameter explicitly.
What systems are affected by CVE-2008-1692?
CVE-2008-1692 affects Eterm version 0.9.4 if the DISPLAY environment variable is not set.
What is the exploit technique associated with CVE-2008-1692?
CVE-2008-1692 can be exploited by local users who hijack X11 connections through a misconfigured DISPLAY setting.
Is CVE-2008-1692 a remote vulnerability?
No, CVE-2008-1692 is a local vulnerability that requires user interaction to exploit.