Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-2713

Опубликовано: 05 авг. 2010
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8

Описание

The vte_sequence_handler_window_manipulation function in vteseq.c in libvte (aka libvte9) in VTE 0.25.1 and earlier, as used in gnome-terminal, does not properly handle escape sequences, which allows remote attackers to execute arbitrary commands or obtain potentially sensitive information via a (1) window title or (2) icon title sequence. NOTE: this issue exists because of a CVE-2003-0070 regression.

РелизСтатусПримечание
dapper

not-affected

devel

released

1:0.24.1-1ubuntu2
hardy

not-affected

jaunty

released

1:0.20.0-0ubuntu2.1
karmic

released

1:0.22.2-0ubuntu2.1
lucid

released

1:0.23.5-0ubuntu1.1
upstream

released

0.24.3

Показывать по

EPSS

Процентиль: 75%
0.00873
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

redhat
больше 15 лет назад

The vte_sequence_handler_window_manipulation function in vteseq.c in libvte (aka libvte9) in VTE 0.25.1 and earlier, as used in gnome-terminal, does not properly handle escape sequences, which allows remote attackers to execute arbitrary commands or obtain potentially sensitive information via a (1) window title or (2) icon title sequence. NOTE: this issue exists because of a CVE-2003-0070 regression.

nvd
больше 15 лет назад

The vte_sequence_handler_window_manipulation function in vteseq.c in libvte (aka libvte9) in VTE 0.25.1 and earlier, as used in gnome-terminal, does not properly handle escape sequences, which allows remote attackers to execute arbitrary commands or obtain potentially sensitive information via a (1) window title or (2) icon title sequence. NOTE: this issue exists because of a CVE-2003-0070 regression.

debian
больше 15 лет назад

The vte_sequence_handler_window_manipulation function in vteseq.c in l ...

github
больше 3 лет назад

The vte_sequence_handler_window_manipulation function in vteseq.c in libvte (aka libvte9) in VTE 0.25.1 and earlier, as used in gnome-terminal, does not properly handle escape sequences, which allows remote attackers to execute arbitrary commands or obtain potentially sensitive information via a (1) window title or (2) icon title sequence. NOTE: this issue exists because of a CVE-2003-0070 regression.

EPSS

Процентиль: 75%
0.00873
Низкий

6.8 Medium

CVSS2