← Back

CVE-2008-1142

nvd nist
Published: Apr 7, 2008Modified: Apr 23, 2026

JSON object

Loading...
3.7
Vector
AV:L/AC:H/Au:N/C:P/I:P/A:P
Exploitability: 1.9 / Impact: 6.4
Source: NVD

Description

rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: it was later reported that rxvt-unicode, mrxvt, aterm, multi-aterm, and wterm are also affected. NOTE: realistic attack scenarios require that the victim enters a command on the wrong machine.

Affected (118)

Products: Aterm: Aterm · Eterm: Eterm · Mrxvt: Mrxvt · +4 more
Show all products
1 product
Aterm
1 product
Eterm
1 product
Mrxvt
1 product
Multi Aterm
1 product
Rxvt
1 product
Rxvt Unicode
1 product
Wterm
Configuration A
118 vulnerable
Vulnerable SoftwareAffected Versions
Aterm
Up to 1.0.0
Version 0.1.0
Version 0.1.1
Version 0.2.0
Version 0.3.0
Version 0.3.1
Version 0.3.2
Version 0.3.3
Version 0.3.4
Version 0.3.5
Version 0.3.6
Version 0.4.0
Version 0.4.1
Version 0.4.2
Version 1.00 beta1
Version 1.00 beta2
Version 1.00 beta3
Version 1.00 beta4
Eterm
Up to 0.9.3
Version 0.9.2
Mrxvt
Up to 0.5.2
Version 0.4.2
Multi Aterm
Up to 0.2
Version 0.0.1
Version 0.0.3
Version 0.0.4
Version 0.0.5
Version 0.1
Rxvt
Up to 2.7.9
Version 2.6.1
Version 2.6.2
Version 2.6.3
Version 2.6.4
Version 2.7.5
Version 2.7.6
Version 2.7.7
Version 2.7.8
Rxvt Unicode
Up to 9.01
Version 1.0
Version 1.1
Version 1.2
Version 1.3
Version 1.4
Version 1.5
Version 1.6
Version 1.7
Version 1.8
Version 1.91
Version 1.9
Version 2.0
Version 2.1
Version 2.2
Version 2.3
Version 2.4
Version 2.5
Version 2.6
Version 2.7
Version 2.8
Version 2.9
Version 3.0
Version 3.1
Version 3.2
Version 3.3
Version 3.4
Version 3.5
Version 3.6
Version 3.7
Version 3.8
Version 3.9
Version 4.0
Version 4.1
Version 4.2
Version 4.3
Version 4.4
Version 4.5
Version 4.6
Version 4.7
Version 4.8
Version 4.9
Version 5.0
Version 5.1
Version 5.2
Version 5.3
Version 5.4
Version 5.5
Version 5.6
Version 5.7
Version 5.8
Version 5.9
Version 6.0
Version 6.1
Version 6.2
Version 6.3
Version 7.0
Version 7.1
Version 7.2
Version 7.3
Version 7.4
Version 7.5
Version 7.6
Version 7.7
Version 7.8
Version 7.9
Version 8.0
Version 8.1
Version 8.2
Version 8.3
Version 8.4
Version 8.5
Version 8.5a
Version 8.6
Version 8.7
Version 8.8
Version 8.9
Version 9.0
Wterm
Up to 6.2.8a2
Version 6.2.5
Version 6.2.6

Related CWEs

References (28)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch

Timeline

No history available yet.