CVE-2016-10369
HIGHlxterminal < 0.3.0 - Denial of Service via Insecure /tmp Socket File
Title source: llmDescription
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).
References (3)
Core 3
Core References
Various Sources x_refsource_misc
https://git.lxde.org/gitweb/?p=lxde/lxterminal.git%3Ba=commit%3Bh=f99163c6ff8b2f57c5f37b1ce5d62cf7450d4648
Third Party Advisory x_refsource_misc
https://unix.stackexchange.com/questions/333539/lxterminal-in-the-netstat-output/333578
Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://bugs.debian.org/862098
Scores
CVSS v3
7.8
EPSS
0.0032
EPSS Percentile
23.7%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-284
Status
published
Products (1)
lxterminal_project/lxterminal
< 0.3.0
Published
May 08, 2017
Tracked Since
Feb 18, 2026