Multi Gnome Terminal Information Leak Vulnerability
BID:11117
Info
Multi Gnome Terminal Information Leak Vulnerability
| Bugtraq ID: | 11117 |
| Class: | Environment Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 06 2004 12:00AM |
| Updated: | Sep 06 2004 12:00AM |
| Credit: | Announced in Gentoo advisory GLSA-200409-10. |
| Vulnerable: |
Gnome Multi Terminal Gnome Multi Terminal 1.6.2 -r1 |
| Not Vulnerable: | |
Discussion
Multi Gnome Terminal Information Leak Vulnerability
It has been reported that Multi Gnome Terminal may output active user keystrokes to a file that is potentially world readable. According to the report, Gnome Multi Terminal "has been known to" (i.e. under some circumstances, which are unclear at this time) write keystroke data to ~/.xsession-errors. As this file can be world readable, this may result in a leak of confidential information to other local users.
It has been reported that Multi Gnome Terminal may output active user keystrokes to a file that is potentially world readable. According to the report, Gnome Multi Terminal "has been known to" (i.e. under some circumstances, which are unclear at this time) write keystroke data to ~/.xsession-errors. As this file can be world readable, this may result in a leak of confidential information to other local users.
Exploit / POC
Multi Gnome Terminal Information Leak Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Multi Gnome Terminal Information Leak Vulnerability
Solution:
Gentoo has issued updates that can be applied using the following procedure:
# emerge sync
# emerge -pv ">=x11-terms/multi-gnome-terminal-1.6.2-r1"
# emerge ">=x11-terms/multi-gnome-terminal-1.6.2-r1"
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Gentoo has issued updates that can be applied using the following procedure:
# emerge sync
# emerge -pv ">=x11-terms/multi-gnome-terminal-1.6.2-r1"
# emerge ">=x11-terms/multi-gnome-terminal-1.6.2-r1"
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Multi Gnome Terminal Information Leak Vulnerability
References:
References: