4.6
CVSSv2

CVE-2015-8971

Published: 23/01/2017 Updated: 24/02/2020
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Terminology 0.7.0 allows remote malicious users to execute arbitrary commands via escape sequences that modify the window title and then are written to the terminal, a similar issue to CVE-2003-0063.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 8.0

enlightenment terminology 0.7.0

Vendor Advisories

Debian Bug report logs - #843434 terminology: CVE-2015-8971: Escape Sequence Command Execution vulnerability Package: src:terminology; Maintainer for src:terminology is Debian Pkg-e Team <pkg-e-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 6 Nov 2016 17:15:01 UTC Se ...