CVE-2008-1692
EPSS 0.31%
描述
Eterm 0.9.4 opens a terminal window on :0 if -display is not specified and the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: realistic attack scenarios require that the victim enters a command on the wrong machine.
如何修補 CVE-2008-1692
要修補 CVE-2008-1692,請將受影響套件升級到下列已修補版本。
- Debian/eterm—升級至 0.9.4.0debian1-2.1 或更新版本
CVE-2008-1692 正在被利用嗎?
低 — EPSS 為 0.3%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 0.9.4.0debian1-2.1