4.6
CVSSv2

CVE-2006-5969

Published: 17/11/2006 Updated: 14/02/2024
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

CRLF injection vulnerability in the evalFolderLine function in fvwm 2.5.18 and previous versions allows local users to execute arbitrary commands via carriage returns in a directory name, which is not properly handled by fvwm-menu-directory, a variant of CVE-2003-1308.

Vulnerable Product Search on Vulmon Subscribe to Product

fvwm fvwm

Vendor Advisories

Debian Bug report logs - #400303 fvwm: CRLF injection in fvwm-menu-directory (CVE-2006-5969) also in stable Package: fvwm; Maintainer for fvwm is Jaimos Skriletz <jaimosskriletz@gmailcom>; Source for fvwm is src:fvwm (PTS, buildd, popcon) Reported by: abe@physethzch (Axel Beckert) Date: Sat, 25 Nov 2006 04:33:03 UTC Se ...