Description
The xterm terminal emulator in XFree86 4.2.0 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2003-0059 | The xterm terminal emulator in XFree86 4.2.0 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands. |
References
History
Tue, 29 Oct 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-150 |
Tue, 29 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xfree86
Xfree86 xfree86 |
|
| CPEs | cpe:2.3:a:xfree86:xfree86:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xfree86
Xfree86 xfree86 |
|
| Metrics |
ssvc
|
Thu, 22 Aug 2024 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-150 | |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-29T14:05:49.769Z
Reserved: 2003-02-04T00:00:00.000Z
Link: CVE-2003-0063
Updated: 2024-08-08T01:43:35.241Z
Status : Modified
Published: 2003-03-03T05:00:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2003-0063
OpenCVE Enrichment
No data.
Weaknesses
EUVD