xterm Psuedo Terminal Insecure Permissions Local Insecure Permission Weakness
BID:26710
Info
xterm Psuedo Terminal Insecure Permissions Local Insecure Permission Weakness
| Bugtraq ID: | 26710 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-2797 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 05 2007 12:00AM |
| Updated: | Dec 06 2007 03:12PM |
| Credit: | Klaus Ethgen is credited with the discovery of this vulnerability. |
| Vulnerable: |
X.org xterm 215 X.org xterm 214 X.org xterm 208-3.1 X.org xterm 192-7.el4 rPath rPath Linux 1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux AS 4 Redhat Desktop 4.0 Foresight Linux Foresight Linux 1.1 Avaya Messaging Storage Server MSS 3.0 Avaya Messaging Storage Server 3.1 Avaya Message Networking MN 3.1 Avaya Intuity AUDIX LX 2.0 |
| Not Vulnerable: | |
Discussion
Exploit / POC
xterm Psuedo Terminal Insecure Permissions Local Insecure Permission Weakness
An attacker can exploit this issue by gaining local interactive access to affected computers.
An attacker can exploit this issue by gaining local interactive access to affected computers.
Solution / Fix
xterm Psuedo Terminal Insecure Permissions Local Insecure Permission Weakness
Solution:
Please see the references for more information.
Solution:
Please see the references for more information.
References
xterm Psuedo Terminal Insecure Permissions Local Insecure Permission Weakness
References:
References:
- xterm Homepage (xterm)
- Avaya Security Advisory ASA-2007-490 (Avaya)
- Red Hat Linux Security Advisory RHSA-2007:0701-2 (Red Hat)