CVE-2007-0823

UnknownEPSS 0.44%

Last modified

CVE-2007-0823 is a vulnerability of currently unknown severity. xterm on Slackware Linux 10.2 stores information that had been displayed for a different user account using the same xterm process, which might allow local users to bypass file permissions and read other users' files, or obtain other sensitive information, by reading the xterm process memory. NOTE: it could be argued that this is an expected consequence of multiple users sharing the same interactive process, in which case this is not a vulnerability.. EPSS estimates a 0.44% chance of exploitation in the next 30 days.

Description

xterm on Slackware Linux 10.2 stores information that had been displayed for a different user account using the same xterm process, which might allow local users to bypass file permissions and read other users' files, or obtain other sensitive information, by reading the xterm process memory. NOTE: it could be argued that this is an expected consequence of multiple users sharing the same interactive process, in which case this is not a vulnerability.

Metrics

EPSS Probability
0.44%

34.9th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
SlackwareSlackware Linux10.2

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2007-0823?
xterm on Slackware Linux 10.2 stores information that had been displayed for a different user account using the same xterm process, which might allow local users to bypass file permissions and read other users' files, or obtain other sensitive information, by reading the xterm process memory. NOTE: it could be argued that this is an expected consequence of multiple users sharing the same interactive process, in which case this is not a vulnerability.
How severe is CVE-2007-0823?
Severity scoring for CVE-2007-0823 is pending analysis. The EPSS model estimates a 0.44% probability of exploitation in the next 30 days.
How do I fix CVE-2007-0823?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2007-0823?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST