Vulnerability Name: | CVE-2006-0126 (CCN-23998) | ||||||||
Assigned: | 2006-01-05 | ||||||||
Published: | 2006-01-05 | ||||||||
Updated: | 2011-03-08 | ||||||||
Summary: | rxvt-unicode before 6.3, on certain platforms that use openpty and non-Unix pty devices such as Linux and most BSD platforms, does not maintain the intended permissions of tty devices, which allows local users to gain read and write access to the devices. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P) 3.4 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-0126 Source: CCN Type: rxvt-unicode Web site Index of /rxvt-unicode Source: CONFIRM Type: UNKNOWN http://dist.schmorp.de/rxvt-unicode/Changes Source: CCN Type: SA18301 rxvt-unicode TTY Device Insecure Permissions Vulnerability Source: SECUNIA Type: Patch, Vendor Advisory 18301 Source: OSVDB Type: Patch 22223 Source: CCN Type: OSVDB ID: 22223 rxvt-unicode non-unix pty TTY Device Permission Weakness Source: VUPEN Type: UNKNOWN ADV-2006-0052 Source: XF Type: UNKNOWN rxvt-unicode-tty-insecure-permissions(23998) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |