oss-sec mailing list archives

request CVE id: insecure handling of DISPLAY in rxvt


From: Nico Golde <oss-security+ml () ngolde de>
Date: Tue, 4 Mar 2008 16:10:02 +0100

Hi all,
Steve, can I get a CVE id for the following issue in rxvt?

"If the DISPLAY environment is not set, rxvt opens an xterm 
on :0, which on some headless login-server means anyone can setup 
an fake X server waiting for someone loggin in without X 
forwarding to start rxvt by some mistake or by some program (thus 
without even noticing) and getting full shell access to that other 
account."

This is Debian bug 469296[0].

It should be a good idea to check other terminal emulators 
as well.

[0] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=469296

Cheers
Nico

-- 
Nico Golde - http://www.ngolde.de - nion () jabber ccc de - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.

Attachment: _bin
Description:


Current thread: