PT-2022-16007 · Swiftterm · Swiftterm
David Leadbeater
·
Published
2022-12-02
·
Updated
2023-07-14
·
CVE-2022-23465
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SwiftTerm versions prior to a94e6b24d24ce9680ad79884992e1dff8e150a31
Description
The issue allows an attacker to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal. This could happen when the user views a file containing the malicious sequence, potentially allowing the attacker to execute arbitrary commands.
Recommendations
For versions prior to a94e6b24d24ce9680ad79884992e1dff8e150a31, update to version a94e6b24d24ce9680ad79884992e1dff8e150a31 or later, which contains a patch for this issue. As a temporary workaround, consider avoiding viewing files that may contain malicious character escape sequences until the update is applied.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Swiftterm