unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).
CVSS Details
- CVSS 3.0 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade lxterminal | Aug 22, 2024 | May 8, 2017 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | May 8, 2017 |
| Debian | — | Upgrade lxterminal | May 10, 2017 | May 8, 2017 |
| Suse | — | Upgrade lxterminal-debugsourceUpgrade lxterminal-langUpgrade lxterminalUpgrade lxterminal-debuginfo | Jan 24, 2018 | May 8, 2017 |
| Ubuntu | — | Upgrade lxterminal | Nov 19, 2024 | May 8, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub