The xterm terminal emulator in XFree86 4.2.0 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the users terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.
Name | Vendor | Start Version | End Version |
---|---|---|---|
X11r6 | Xfree86_project | 4.1.0 | 4.1.0 |
X11r6 | Xfree86_project | 4.0.3 | 4.0.3 |
X11r6 | Xfree86_project | 4.2.1 | 4.2.1 |
X11r6 | Xfree86_project | 4.0 | 4.0 |
X11r6 | Xfree86_project | 4.0.1 | 4.0.1 |
X11r6 | Xfree86_project | 4.2.0 | 4.2.0 |