LWN.net Logo

multi-gnome-terminal: Information leak

Package(s):multi-gnome-terminal CVE #(s):
Created:September 6, 2004 Updated:September 8, 2004
Description: multi-gnome-terminal contains debugging code that has been known to output active keystrokes to a potentially unsafe location. Output has been seen to show up in the '.xsession-errors' file in the users home directory. Since this file is world-readable on many machines, this bug has the potential to leak sensitive information to anyone using the system. Any authorized user on the local machine has the ability to read any critical data that has been entered into the terminal, including passwords.
Alerts:
Gentoo 200409-10 2004-09-06

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds