PT-2003-1114 · Rxvt · Rxvt

H D Moore

·

Published

2003-03-03

·

Updated

2016-10-18

·

CVE-2003-0066

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions rxvt versions 2.7.8 and earlier
Description The issue allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal. This could happen when the user views a file containing the malicious sequence, potentially allowing the attacker to execute arbitrary commands. Exploitation of the vulnerabilities may lead to disruption of confidentiality, integrity, and availability of protected information and can be carried out remotely.
Recommendations For versions 2.7.8 and earlier, consider disabling the ability to modify the window title via character escape sequences until a patch is available. Restrict access to potentially malicious files that could contain the harmful sequence to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-08213
CVE-2003-0066

Affected Products

Rxvt