LWN.net Logo

Pardus alert 2010-111 (vte)

From:  Eren Turkay <eren@pardus.org.tr>
To:  pardus-security@pardus.org.tr
Subject:  [Pardus-security] [PLSA 2010-111] Vte: Arbitrary Code Execution
Date:  Thu, 12 Aug 2010 23:05:44 +0300 (EEST)
Message-ID:  <20100812200544.67A69A7AC40@lider.pardus.org.tr>
Archive-link:  Article, Thread

------------------------------------------------------------------------ Pardus Linux Security Advisory 2010-111 security@pardus.org.tr ------------------------------------------------------------------------ Date: 2010-08-11 Severity: 4 Type: Local ------------------------------------------------------------------------ Summary ======= A vulnerability has been fixed in Vte, which an allow malicious users to execute arbitrary code Description =========== CVE-2010-2713: The vte_sequence_handler_window_manipulation function in vteseq.c in libvte (aka libvte9) in VTE 0.25.1 and earlier, as used in gnome-terminal, does not properly handle escape sequences, which allows remote attackers to execute arbitrary commands or obtain potentially sensitive information via a (1) window title or (2) icon title sequence. NOTE: this issue exists because of a CVE-2003-0070 regression. Affected packages: Pardus 2009: vte, all before 0.20.5-8-4 Resolution ========== There are update(s) for vte. You can update them via Package Manager or with a single command from console: pisi up vte References ========== * http://bugs.pardus.org.tr/show_bug.cgi?id=13919 ------------------------------------------------------------------------ _______________________________________________ Pardus-security mailing list Pardus-security@pardus.org.tr http://liste.pardus.org.tr/mailman/listinfo/pardus-security


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds