A vulnerability in rxvt allowed it to open a terminal on :0 if the
environment variable was not set, which could be used by a local
user to hijack X11 connections (CVE-2008-1142). This issue also
affects aterm.
The updated packages have been patched to correct this issue.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cg ... -2008-1142
_______________________________________________________________________