PT-2003-1112 · Rxvt · Rxvt

H D Moore

·

Published

2003-03-03

·

Updated

2016-10-18

·

CVE-2003-0022

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions rxvt version 2.7.8
Description The issue concerns the "screen dump" feature in rxvt, which allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to a user's terminal. This can occur, for example, when a user views a file containing the malicious sequence. Multiple vulnerabilities in the rxvt package may lead to breaches of confidentiality, integrity, and availability of protected information, and these vulnerabilities can be exploited remotely.
Recommendations For rxvt version 2.7.8, consider disabling the "screen dump" feature as a temporary workaround until a patch is available. Restrict access to sensitive files and terminals to minimize the risk of exploitation. Avoid using the terminal to view untrusted files that may contain malicious character escape sequences until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-08213
CVE-2003-0022

Affected Products

Rxvt