Vulnerability Name:

CVE-2007-0823 (CCN-32465)

Assigned:2007-02-01
Published:2007-02-01
Updated:2008-11-15
Summary:xterm on Slackware Linux 10.2 stores information that had been displayed for a different user account using the same xterm process, which might allow local users to bypass file permissions and read other users' files, or obtain other sensitive information, by reading the xterm process memory.
Note: it could be argued that this is an expected consequence of multiple users sharing the same interactive process, in which case this is not a vulnerability.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:1.9 Low (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N)
1.6 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N/E:POC/RL:U/RC:UR)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
1.8 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:U/RC:UR)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Obtain Information
References:Source: CCN
Type: Full-Disclosure Mailing List, Thu Feb 01 2007 - 14:12:03 CST
umount crash and xterm (kind of) information leak!

Source: FULLDISC
Type: UNKNOWN
20070201 umount crash and xterm (kind of) information leak!

Source: MITRE
Type: CNA
CVE-2007-0823

Source: MISC
Type: Exploit
http://gotfault.wordpress.com/2007/02/01/a-funny-case/

Source: OSVDB
Type: UNKNOWN
33651

Source: CCN
Type: OSVDB ID: 33651
Linux xterm Process Memory Information Disclosure

Source: CCN
Type: Slackware Linux Web site
The Slackware Linux Project

Source: XF
Type: UNKNOWN
linux-xterm-information-disclosure(32465)

Vulnerable Configuration:Configuration 1:
  • cpe:/o:slackware:slackware_linux:10.2:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:slackware:slackware_linux:10.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    slackware slackware linux 10.2
    slackware slackware linux 10.2