6.8
CVSSv2

CVE-2010-2713

Published: 05/08/2010 Updated: 09/09/2010
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The vte_sequence_handler_window_manipulation function in vteseq.c in libvte (aka libvte9) in VTE 0.25.1 and previous versions, as used in gnome-terminal, does not properly handle escape sequences, which allows remote malicious users to execute arbitrary commands or obtain potentially sensitive information via a (1) window title or (2) icon title sequence. NOTE: this issue exists because of a CVE-2003-0070 regression.

Vulnerable Product Search on Vulmon Subscribe to Product

nalin dahyabhai vte

nalin dahyabhai vte 0.11.21

nalin dahyabhai vte 0.12.2

nalin dahyabhai vte 0.14.2

nalin dahyabhai vte 0.15.0

nalin dahyabhai vte 0.16.14

nalin dahyabhai vte 0.17.4

nalin dahyabhai vte 0.20.5

nalin dahyabhai vte 0.22.5

nalin dahyabhai vte 0.24.3

Vendor Advisories

arbitrary command execution via terminal escape codes ...