PT-2022-16007 · Swiftterm · Swiftterm

David Leadbeater

·

Published

2022-12-02

·

Updated

2023-07-14

·

CVE-2022-23465

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions SwiftTerm versions prior to a94e6b24d24ce9680ad79884992e1dff8e150a31
Description The issue allows an attacker to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal. This could happen when the user views a file containing the malicious sequence, potentially allowing the attacker to execute arbitrary commands.
Recommendations For versions prior to a94e6b24d24ce9680ad79884992e1dff8e150a31, update to version a94e6b24d24ce9680ad79884992e1dff8e150a31 or later, which contains a patch for this issue. As a temporary workaround, consider avoiding viewing files that may contain malicious character escape sequences until the update is applied.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2022-23465
GHSA-JQ43-Q8MX-R7MQ

Affected Products

Swiftterm