VYPR
Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026

CVE-2004-2215

CVE-2004-2215

Description

RXVT-Unicode 3.4 and 3.5 fail to close file descriptors, allowing local users to access other users' terminals and potentially escalate privileges.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

RXVT-Unicode 3.4 and 3.5 fail to close file descriptors, allowing local users to access other users' terminals and potentially escalate privileges.

Vulnerability

RXVT-Unicode versions 3.4 and 3.5 contain a vulnerability where file descriptors are not properly closed after use. This flaw occurs in the terminal emulator's process handling, leaving file descriptors open that should be restricted to the owning user's session. The affected versions are 3.4 and 3.5 [1].

Exploitation

An attacker must have local access to the system and be able to run processes on the same machine. By exploiting the leaked file descriptors, the attacker can read from or write to the terminal sessions of other users who are running the same vulnerable version of RXVT-Unicode. No special privileges or user interaction beyond local shell access is required [1].

Impact

Successful exploitation allows the attacker to intercept or inject data into other users' terminal sessions, leading to information disclosure (e.g., reading passwords or sensitive output) and potentially privilege escalation if the target user has higher privileges. The attacker gains the ability to interact with the terminal of another user, which can compromise the confidentiality and integrity of that session [1].

Mitigation

Users should upgrade to a version of RXVT-Unicode that properly closes file descriptors. Since the vulnerability was disclosed in 2004, later versions (e.g., 3.6 or newer) are expected to contain the fix. If upgrading is not possible, limiting local access to trusted users and monitoring for unusual terminal activity may reduce risk. No workaround is documented in the available references [1].

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • cpe:2.3:a:marc_lehmann:rxvt-unicode:3.4:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:marc_lehmann:rxvt-unicode:3.4:*:*:*:*:*:*:*
    • cpe:2.3:a:marc_lehmann:rxvt-unicode:3.5:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.