PT-2024-27980 · Iterm2 · Iterm2
David Leadbeater
+1
·
Published
2024-06-16
·
Updated
2024-07-14
·
CVE-2024-38396
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
iTerm2 versions 3.5.x through 3.5.1
Description
An issue was discovered in iTerm2 that allows an attacker to inject arbitrary code into the terminal by abusing title reporting and tmux integration. This is possible due to the unfiltered use of an escape sequence to report a window title, in combination with the built-in tmux integration feature, which is enabled by default.
Recommendations
For iTerm2 versions 3.5.x through 3.5.1, update to version 3.5.2 or later to resolve the issue. As a temporary workaround, consider disabling the tmux integration feature until a patch is available. Restrict access to the terminal to minimize the risk of exploitation. Avoid using the title reporting feature in the affected versions until the issue is resolved.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Iterm2