PT-2003-1061 · Gnome · Vte-Devel+1

Daniel Ahlberg

·

Published

2003-02-24

·

Updated

2016-10-18

·

CVE-2003-0070

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions vte versions 0.8.19 vte-devel versions 0.8.19
Description The issue allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal. This could enable the attacker to execute arbitrary commands, for example, when the user views a file containing the malicious sequence. Exploitation of this issue can be done remotely and may lead to a breach of confidentiality, integrity, and availability of protected information.
Recommendations For vte version 0.8.19, consider disabling the use of character escape sequences in the terminal emulator until a patch is available. For vte-devel version 0.8.19, restrict the insertion of modified window titles back into the command line to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-07916
BDU:2015-07917
CVE-2003-0070

Affected Products

Vte
Vte-Devel