PT-2023-7566 · Iterm2 · Iterm2

Solid-Snail

·

Published

2023-10-21

·

Updated

2023-10-31

·

CVE-2023-46301

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions iTerm2 versions prior to 3.4.20
Description The issue is related to the mishandling of certain escape sequences related to upload, which can allow potentially remote code execution. This is due to a lack of proper output encoding or escaping mechanism in the terminal emulator. An attacker could exploit this issue to execute arbitrary code.
Recommendations For versions prior to 3.4.20, update to version 3.4.20 or later to resolve the issue. As a temporary workaround, consider disabling the handling of escape sequences related to upload until a patch is available. Restrict access to potentially vulnerable features to minimize the risk of exploitation.

Exploit

Fix

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

BDU:2023-08622
CVE-2023-46301

Affected Products

Iterm2