CVE-2016-10369 Information
Feb 14, 2021
cve
Description
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file allowing a local user to cause a denial of service (preventing terminal launch) or possibly have other impact (bypassing terminal access control).
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://bugs.debian.org/862098 https://git.lxde.org/gitweb/?p=lxde/lxterminal.git;a=commit;h=f99163c6ff8b2f57c5f37b1ce5d62cf7450d4648 https://unix.stackexchange.com/questions/333539/lxterminal-in-the-netstat-output/333578
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: