PT-2014-2121 · Gnome · Gnome-Terminal

Jan Lieskovsky

·

Publicado

2014-05-21

·

Atualizado

2018-10-30

·

CVE-2011-2198

CVSS v2.0

3.5

Baixa

VetorAV:N/AC:M/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions gnome-terminal (vte) versions prior to 0.28.1
Description The issue allows remote authenticated users to cause a denial of service, resulting in CPU and memory consumption and a crash, via a crafted file. This can be achieved by including a specific string, such as "033[100000000000000000@", in the file.
Recommendations For versions prior to 0.28.1, update to version 0.28.1 or later to resolve the issue.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-2198

Produtos afetados

Gnome-Terminal