GLSA-200409-10 : multi-gnome-terminal: Information leak

medium Nessus Plugin ID 14669

Synopsis

The remote Gentoo host is missing one or more security-related patches.

Description

The remote host is affected by the vulnerability described in GLSA-200409-10 (multi-gnome-terminal: Information leak)

multi-gnome-terminal contains debugging code that has been known to output active keystrokes to a potentially unsafe location. Output has been seen to show up in the '.xsession-errors' file in the user's home directory. Since this file is world-readable on many machines, this bug has the potential to leak sensitive information to anyone using the system.
Impact :

Any authorized user on the local machine has the ability to read any critical data that has been entered into the terminal, including passwords.
Workaround :

There is no known workaround at this time.

Solution

All multi-gnome-terminal users should upgrade to the latest version:
# emerge sync # emerge -pv '>=x11-terms/multi-gnome-terminal-1.6.2-r1' # emerge '>=x11-terms/multi-gnome-terminal-1.6.2-r1'

See Also

https://security.gentoo.org/glsa/200409-10

Plugin Details

Severity: Medium

ID: 14669

File Name: gentoo_GLSA-200409-10.nasl

Version: 1.17

Type: local

Published: 9/6/2004

Updated: 1/6/2021

Supported Sensors: Nessus

Vulnerability Information

CPE: p-cpe:/a:gentoo:linux:multi-gnome-terminal, cpe:/o:gentoo:linux

Required KB Items: Host/local_checks_enabled, Host/Gentoo/release, Host/Gentoo/qpkg-list

Patch Publication Date: 9/6/2004

Vulnerability Publication Date: 9/6/2004

Reference Information

GLSA: 200409-10