PT-2023-7566 · Iterm2 · Iterm2
Solid-Snail
·
Published
2023-10-21
·
Updated
2023-10-31
·
CVE-2023-46301
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
iTerm2 versions prior to 3.4.20
Description
The issue is related to the mishandling of certain escape sequences related to upload, which can allow potentially remote code execution. This is due to a lack of proper output encoding or escaping mechanism in the terminal emulator. An attacker could exploit this issue to execute arbitrary code.
Recommendations
For versions prior to 3.4.20, update to version 3.4.20 or later to resolve the issue. As a temporary workaround, consider disabling the handling of escape sequences related to upload until a patch is available. Restrict access to potentially vulnerable features to minimize the risk of exploitation.
Exploit
Fix
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Iterm2