CVE-2009-0141

MEDIUM

XTerm <10.5.6 - Local Info Disclosure

Title source: llm

Description

XTerm in Apple Mac OS X 10.4.11 and 10.5.6, when used with luit, creates tty devices with insecure world-writable permissions, which allows local users to write to the Xterm of another user.

Scores

CVSS v3 5.5
EPSS 0.0005
EPSS Percentile 14.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Classification

CWE
CWE-732
Status draft

Affected Products (4)

apple/mac_os_x
apple/mac_os_x
apple/mac_os_x_server
apple/mac_os_x_server

Timeline

Published Feb 13, 2009
Tracked Since Feb 18, 2026