PT-2024-27633 · Gnome+5 · Gnome Vte+5

Alan Coopersmith

·

Published

2024-02-08

·

Updated

2024-08-22

·

CVE-2024-37535

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GNOME VTE versions prior to 0.76.3
Description The issue allows an attacker to cause a denial of service, specifically memory consumption, via a window resize escape sequence. This is related to a historical issue.
Recommendations For versions prior to 0.76.3, update to version 0.76.3 or later to resolve the issue. As a temporary workaround, consider restricting the processing of window resize escape sequences until a patch is available.

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

AZL-42631
AZL-43167
BDU:2026-06680
CVE-2024-37535
MGASA-2024-0219
OESA-2024-1803
OESA-2024-1826
OESA-2024-1827
OESA-2024-1828
OESA-2024-1829
OPENSUSE-SU-2024:14284-1
OPENSUSE-SU-2024_2153-1
OPENSUSE-SU-2024_2180-1
SUSE-SU-2024:2151-1
SUSE-SU-2024:2152-1
SUSE-SU-2024:2153-1
SUSE-SU-2024:2180-1
SUSE-SU-2024_2151-1
SUSE-SU-2024_2152-1
SUSE-SU-2024_2153-1
SUSE-SU-2024_2180-1
USN-6833-1

Affected Products

Debian
Gnome Vte
Linuxmint
Red Os
Suse
Ubuntu