PT-2003-1114 · Rxvt · Rxvt
H D Moore
·
Publicado
2003-03-03
·
Atualizado
2016-10-18
·
CVE-2003-0066
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
rxvt versions 2.7.8 and earlier
Description
The issue allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal. This could happen when the user views a file containing the malicious sequence, potentially allowing the attacker to execute arbitrary commands. Exploitation of the vulnerabilities may lead to disruption of confidentiality, integrity, and availability of protected information and can be carried out remotely.
Recommendations
For versions 2.7.8 and earlier, consider disabling the ability to modify the window title via character escape sequences until a patch is available. Restrict access to potentially malicious files that could contain the harmful sequence to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Rxvt