LOW · 2.1

CVE-2007-2797

xterm, including 192-7.el4 in Red Hat Enterprise Linux and 208-3.1 in Debian GNU/Linux, sets the wrong group ownership of tty devices, which allows local users to write data to other users' terminals.

Vulnerability Description

xterm, including 192-7.el4 in Red Hat Enterprise Linux and 208-3.1 in Debian GNU/Linux, sets the wrong group ownership of tty devices, which allows local users to write data to other users' terminals.

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
RedhatEnterprise LinuxAll versions
XtermXterm192-7.el4
DebianDebian LinuxAll versions

References

FAQ

What is CVE-2007-2797?

CVE-2007-2797 is a vulnerability with a CVSS score of 2.1 (LOW). xterm, including 192-7.el4 in Red Hat Enterprise Linux and 208-3.1 in Debian GNU/Linux, sets the wrong group ownership of tty devices, which allows local users to write data to other users' terminals.

How severe is CVE-2007-2797?

CVE-2007-2797 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-2797?

Check the references section above for vendor advisories and patch information. Affected products include: Redhat Enterprise Linux, Xterm Xterm, Debian Debian Linux.