MDVSA-2010:161 -- Mandriva vteID: oval:org.secpod.oval:def:300071 | Date: (C)2012-01-07 (M)2021-07-09 |
Class: PATCH | Family: unix |
A vulnerability has been found and corrected in vte: The vte_sequence_handler_window_manipulation function in vteseq.c in libvte in VTE 0.25.1 and earlier, as used in gnome-terminal, does not properly handle escape sequences, which allows remote attackers to execute arbitrary commands or obtain potentially sensitive information via a window title or icon title sequence. NOTE: this issue exists because of a CVE-2003-0070 regression . The updated packages have been patched to correct this issue.
Platform: |
Mandriva Linux 2010.0 |
Mandriva Linux 2010.1 |
Mandriva Linux 2009.1 |