CVE-2008-1142

UnknownEPSS 0.36%

Last modified

CVE-2008-1142 is a vulnerability of currently unknown severity. rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: it was later reported that rxvt-unicode, mrxvt, aterm, multi-aterm, and wterm are also affected. EPSS estimates a 0.36% chance of exploitation in the next 30 days.

Description

rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: it was later reported that rxvt-unicode, mrxvt, aterm, multi-aterm, and wterm are also affected. NOTE: realistic attack scenarios require that the victim enters a command on the wrong machine.

Metrics

EPSS Probability
0.36%

28.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
AtermAterm<= 1.0.0
AtermAterm0.1.0
AtermAterm0.1.1
AtermAterm0.2.0
AtermAterm0.3.0
AtermAterm0.3.1
AtermAterm0.3.2
AtermAterm0.3.3
AtermAterm0.3.4
AtermAterm0.3.5
AtermAterm0.3.6
AtermAterm0.4.0
AtermAterm0.4.1
AtermAterm0.4.2
AtermAterm1.00Beta1
EtermEterm<= 0.9.3
EtermEterm0.9.2
MrxvtMrxvt<= 0.5.2
MrxvtMrxvt0.4.2
Multi-AtermMulti-Aterm<= 0.2
Multi-AtermMulti-Aterm0.0.1
Multi-AtermMulti-Aterm0.0.3
Multi-AtermMulti-Aterm0.0.4
Multi-AtermMulti-Aterm0.0.5
Multi-AtermMulti-Aterm0.1
RxvtRxvt<= 2.7.9
RxvtRxvt2.6.1
RxvtRxvt2.6.2
RxvtRxvt2.6.3
RxvtRxvt2.6.4
RxvtRxvt2.7.5
RxvtRxvt2.7.6
RxvtRxvt2.7.7
RxvtRxvt2.7.8
Rxvt-UnicodeRxvt-Unicode<= 9.01
Rxvt-UnicodeRxvt-Unicode1.0
Rxvt-UnicodeRxvt-Unicode1.1
Rxvt-UnicodeRxvt-Unicode1.2
Rxvt-UnicodeRxvt-Unicode1.3
Rxvt-UnicodeRxvt-Unicode1.4
Rxvt-UnicodeRxvt-Unicode1.5
Rxvt-UnicodeRxvt-Unicode1.6
Rxvt-UnicodeRxvt-Unicode1.7
Rxvt-UnicodeRxvt-Unicode1.8
Rxvt-UnicodeRxvt-Unicode1.9
Rxvt-UnicodeRxvt-Unicode1.91
Rxvt-UnicodeRxvt-Unicode2.0
Rxvt-UnicodeRxvt-Unicode2.1
Rxvt-UnicodeRxvt-Unicode2.2
Rxvt-UnicodeRxvt-Unicode2.3

Showing 50 of 115 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2008-1142?
rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: it was later reported that rxvt-unicode, mrxvt, aterm, multi-aterm, and wterm are also affected. NOTE: realistic attack scenarios require that the victim enters a command on the wrong machine.
How severe is CVE-2008-1142?
Severity scoring for CVE-2008-1142 is pending analysis. The EPSS model estimates a 0.36% probability of exploitation in the next 30 days.
How do I fix CVE-2008-1142?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2008-1142?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST