CVE-2008-1142

UnknownEPSS 0.36%

Last modified

CVE-2008-1142 is a vulnerability of currently unknown severity. rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: it was later reported that rxvt-unicode, mrxvt, aterm, multi-aterm, and wterm are also affected. EPSS estimates a 0.36% chance of exploitation in the next 30 days.

Description

rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: it was later reported that rxvt-unicode, mrxvt, aterm, multi-aterm, and wterm are also affected. NOTE: realistic attack scenarios require that the victim enters a command on the wrong machine.

Metrics

EPSS Probability
0.36%

28.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
AtermAterm<= 1.0.0—
AtermAterm0.1.0—
AtermAterm0.1.1—
AtermAterm0.2.0—
AtermAterm0.3.0—
AtermAterm0.3.1—
AtermAterm0.3.2—
AtermAterm0.3.3—
AtermAterm0.3.4—
AtermAterm0.3.5—
AtermAterm0.3.6—
AtermAterm0.4.0—
AtermAterm0.4.1—
AtermAterm0.4.2—
AtermAterm1.00Beta1
EtermEterm<= 0.9.3—
EtermEterm0.9.2—
MrxvtMrxvt<= 0.5.2—
MrxvtMrxvt0.4.2—
Multi-AtermMulti-Aterm<= 0.2—
Multi-AtermMulti-Aterm0.0.1—
Multi-AtermMulti-Aterm0.0.3—
Multi-AtermMulti-Aterm0.0.4—
Multi-AtermMulti-Aterm0.0.5—
Multi-AtermMulti-Aterm0.1—
RxvtRxvt<= 2.7.9—
RxvtRxvt2.6.1—
RxvtRxvt2.6.2—
RxvtRxvt2.6.3—
RxvtRxvt2.6.4—
RxvtRxvt2.7.5—
RxvtRxvt2.7.6—
RxvtRxvt2.7.7—
RxvtRxvt2.7.8—
Rxvt-UnicodeRxvt-Unicode<= 9.01—
Rxvt-UnicodeRxvt-Unicode1.0—
Rxvt-UnicodeRxvt-Unicode1.1—
Rxvt-UnicodeRxvt-Unicode1.2—
Rxvt-UnicodeRxvt-Unicode1.3—
Rxvt-UnicodeRxvt-Unicode1.4—
Rxvt-UnicodeRxvt-Unicode1.5—
Rxvt-UnicodeRxvt-Unicode1.6—
Rxvt-UnicodeRxvt-Unicode1.7—
Rxvt-UnicodeRxvt-Unicode1.8—
Rxvt-UnicodeRxvt-Unicode1.9—
Rxvt-UnicodeRxvt-Unicode1.91—
Rxvt-UnicodeRxvt-Unicode2.0—
Rxvt-UnicodeRxvt-Unicode2.1—
Rxvt-UnicodeRxvt-Unicode2.2—
Rxvt-UnicodeRxvt-Unicode2.3—

Showing 50 of 115 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2008-1142?
rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: it was later reported that rxvt-unicode, mrxvt, aterm, multi-aterm, and wterm are also affected. NOTE: realistic attack scenarios require that the victim enters a command on the wrong machine.
How severe is CVE-2008-1142?
Severity scoring for CVE-2008-1142 is pending analysis. The EPSS model estimates a 0.36% probability of exploitation in the next 30 days.
How do I fix CVE-2008-1142?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2008

Are you affected by CVE-2008-1142?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST