rxvt: unsafe defaulting to using :0 when DISPLAY is unset
Published Apr 7, 2008
3.7
LOWCVSS 2.0
EPSS 0.36%
Description
rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: it was later reported that rxvt-unicode, mrxvt, aterm, multi-aterm, and wterm are also affected. NOTE: realistic attack scenarios require that the victim enters a command on the wrong machine.
Affected products
No data.
- ≤ 1.0.0
- 0.1.0
- 0.1.1
- 0.2.0
- 0.3.0
- 0.3.1
- 0.3.2
- 0.3.3
- 0.3.4
- 0.3.5
- 0.3.6
- 0.4.0
- 0.4.1
- 0.4.2
- 1.00
- 1.00
- 1.00
- 1.00
- ≤ 0.9.3
- 0.9.2
- ≤ 0.5.2
- 0.4.2
- ≤ 0.2
- 0.0.1
- 0.0.3
- 0.0.4
- 0.0.5
- 0.1
- ≤ 2.7.9
- 2.6.1
- 2.6.2
- 2.6.3
- 2.6.4
- 2.7.5
- 2.7.6
- 2.7.7
- 2.7.8
- ≤ 9.01
- 1.0
- 1.1
- 1.2
- 1.3
- 1.4
- 1.5
- 1.6
- 1.7
- 1.8
- 1.9
- 1.91
- 2.0
- 2.1
- 2.2
- 2.3
- 2.4
- 2.5
- 2.6
- 2.7
- 2.8
- 2.9
- 3.0
- 3.1
- 3.2
- 3.3
- 3.4
- 3.5
- 3.6
- 3.7
- 3.8
- 3.9
- 4.0
- 4.1
- 4.2
- 4.3
- 4.4
- 4.5
- 4.6
- 4.7
- 4.8
- 4.9
- 5.0
- 5.1
- 5.2
- 5.3
- 5.4
- 5.5
- 5.6
- 5.7
- 5.8
- 5.9
- 6.0
- 6.1
- 6.2
- 6.3
- 7.0
- 7.1
- 7.2
- 7.3
- 7.4
- 7.5
- 7.6
- 7.7
- 7.8
- 7.9
- 8.0
- 8.1
- 8.2
- 8.3
- 8.4
- 8.5
- 8.5a
- 8.6
- 8.7
- 8.8
- 8.9
- 9.0
- ≤ 6.2.8a2
- 6.2.5
- 6.2.6
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2008-1142 This issue does not affect Red Hat Enterprise Linux 3, 4, or 5. The Red Hat Product Security has rated this issue as having low security impact. Due to the minimal security consequences of this issue, we do not intend to fix this in Red Hat Enterprise Linux 2.1. More information regarding issue severity can be found here: https://access.redhat.com/security/updates/classification/
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:H/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.36% (0.00363) | 27.78th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.36% (0.00363) | 27.95th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.06% (0.00061) | 16.27th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00044) | 11.89th | v3 (v2023.03.01) |
| Jul 2, 2024 | 0.04% (0.00044) | 10.25th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00044) | 8.24th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.55% (0.01547) | 74.98th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.55% (0.01547) | 74.94th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.55% (0.01547) | 72.92th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.55% (0.01547) | 51.82th | v2 (v2022.01.01) |
References (18)
- http://article.gmane.org/gmane.comp.security.oss.general/122 x_refsource_MISC
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=469296 x_refsource_CONFIRMVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/29576 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/30224 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/30225 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/30226 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/30227 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/30229 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/31687 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://security.gentoo.org/glsa/glsa-200805-03.xml vendor-advisoryx_refsource_GENTOO
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:161 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:221 vendor-advisoryx_refsource_MANDRIVA
- http://www.securityfocus.com/bid/28512 vdb-entryx_refsource_BIDPatch
- https://access.redhat.com/security/cve/CVE-2008-1142 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=441462 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2008-1142
- https://www.cve.org/CVERecord?id=CVE-2008-1142
Change history (0)
No recorded changes yet.