PT-2003-1113 · Rxvt · Rxvt

H D Moore

·

Published

2003-03-03

·

Updated

2016-10-18

·

CVE-2003-0023

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions rxvt version 2.7.8
Description The issue allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu. Multiple vulnerabilities in the rxvt package may lead to breaches of confidentiality, integrity, and availability of protected information, and can be exploited remotely.
Recommendations For rxvt version 2.7.8, consider disabling the menuBar feature until a patch is available to prevent the execution of arbitrary commands. Restrict access to the menu options to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-08213
CVE-2003-0023

Affected Products

Rxvt