Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

rPSA-2007-0169-1 xterm

From: rPath Update Announcements <announce-noreply(at)rpath.com>
Date: Thu Aug 23 2007 - 14:52:48 EDT


rPath Security Advisory: 2007-0169-1
Published: 2007-08-23
Products: rPath Linux 1
Rating: Major
Exposure Level Classification:

    Local User Deterministic Unauthorized Access Updated Versions:

    xterm=/conary.rpath.com@rpl:devel//1/202-5.3-1

References:

    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2797     https://issues.rpath.com/browse/RPL-1396

Description:

    Previous versions of the xterm package assigned incorrect ownership and     write permissions to pseudo-terminal devices, permitting local users to     direct output to other users' xterm sessions.     

    Due to xterm's extensive internal processing of escape sequences, this     also permits unauthorized modification of xterm session behavior.

Do you need help?X

Copyright 2007 rPath, Inc.
This file is distributed under the terms of the MIT License. A copy is available at http://www.rpath.com/permanent/mit-license.html Received on Thu Aug 23 16:35:20 2007

This archive was generated by hypermail 2.1.8 : Sun Oct 28 2007 - 06:13:17 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library