PT-2003-1113 · Rxvt · Rxvt
H D Moore
·
Published
2003-03-03
·
Updated
2016-10-18
·
CVE-2003-0023
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
rxvt version 2.7.8
Description
The issue allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu. Multiple vulnerabilities in the rxvt package may lead to breaches of confidentiality, integrity, and availability of protected information, and can be exploited remotely.
Recommendations
For rxvt version 2.7.8, consider disabling the menuBar feature until a patch is available to prevent the execution of arbitrary commands. Restrict access to the menu options to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rxvt