LWN.net Logo

vte: arbitrary code execution

Package(s):vte CVE #(s):CVE-2010-2713
Created:July 16, 2010 Updated:January 19, 2011
Description:

From the Ubuntu advisory:

Janne Snabb discovered that applications using VTE, such as gnome-terminal, did not correctly filter window and icon title request escape codes. If a user were tricked into viewing specially crafted output in their terminal, a remote attacker could execute arbitrary commands with user privileges.

Alerts:
MeeGo MeeGo-SA-10:25 2010-09-03
Mandriva MDVSA-2010:161 2010-08-24
Pardus 2010-111 2010-08-11
SUSE SUSE-SR:2010:014 2010-08-02
openSUSE openSUSE-SU-2010:0423-1 2010-07-22
Ubuntu USN-962-1 2010-07-15
openSUSE openSUSE-SU-2010:0404-1 2010-07-20

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds