« Volver al listado

Eternal Terminal Project

Eternal Terminal Project Eternal Terminal: vulnerabilidades y CVE

Eternal Terminal Project Eternal Terminal tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE7
Últimos 12 meses0
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-23558Media (6.3)0.31%—16 feb 2023
In Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp. For example, a local attacker can create /tmp/.sentry-native-etserver with mode 0777 before the etserver process is started. The attacker can choose…
CVE-2022-48258Media (5.3)1.1%—13 ene 2023
In Eternal Terminal 6.2.1, etserver and etclient have world-readable logfiles.
CVE-2022-48257Media (5.3)0.88%—13 ene 2023
In Eternal Terminal 6.2.1, etserver and etclient have predictable logfile names in /tmp.
CVE-2022-24952Media (6.5)1.6%—16 ago 2022
Several denial of service vulnerabilities exist in Eternal Terminal prior to version 6.2.0, including a DoS triggered remotely by an invalid sequence number and a local bug triggered by invalid input sent directly to…
CVE-2022-24951Alta (7)0.28%—16 ago 2022
A race condition exists in Eternal Terminal prior to version 6.2.0 which allows a local attacker to hijack Eternal Terminal's IPC socket, enabling access to Eternal Terminal clients which attempt to connect in the…
CVE-2022-24950Alta (7.5)1.3%—16 ago 2022
A race condition exists in Eternal Terminal prior to version 6.2.0 that allows an authenticated attacker to hijack other users' SSH authorization socket, enabling the attacker to login to other systems as the targeted…
CVE-2022-24949Alta (7.5)1.0%—16 ago 2022
A privilege escalation to root exists in Eternal Terminal prior to version 6.2.0. This is due to the combination of a race condition, buffer overflow, and logic bug all in PipeSocketHandler::listen().