PT-2022-16007 · Swiftterm · Swiftterm

·

CVE-2022-23465

·

Published

2022-12-02

·

Updated

2023-07-14

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions SwiftTerm versions prior to a94e6b24d24ce9680ad79884992e1dff8e150a31
Description The issue allows an attacker to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal. This could happen when the user views a file containing the malicious sequence, potentially allowing the attacker to execute arbitrary commands.
Recommendations For versions prior to a94e6b24d24ce9680ad79884992e1dff8e150a31, update to version a94e6b24d24ce9680ad79884992e1dff8e150a31 or later, which contains a patch for this issue. As a temporary workaround, consider avoiding viewing files that may contain malicious character escape sequences until the update is applied.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23465
GHSA-JQ43-Q8MX-R7MQ

Affected Products

Swiftterm