7.5
CVSSv2

CVE-2003-0063

Published: 03/03/2003 Updated: 15/06/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The xterm terminal emulator in XFree86 4.2.0 and previous versions allows malicious users to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the malicious user to execute arbitrary commands.

Vulnerable Product Search on Vulmon Subscribe to Product

xfree86 project x11r6 4.1.0

xfree86 project x11r6 4.0.3

xfree86 project x11r6 4.2.1

xfree86 project x11r6 4.0

xfree86 project x11r6 4.0.1

xfree86 project x11r6 4.2.0

Mailing Lists

Hi, I discovered iTerm2 versions 350 and 351 (and some beta versions) have a bug where the preference for whether title reporting is enabled is not respected -- the result is title reporting is always enabled* This is fixed by iTerm2 352, available from iterm2com/downloadshtml -- automatic updates should prompt you to install thi ...