CRLF injection vulnerability in fvwm-menu-directory for fvwm 2.5.x before 2.5.10 and 2.4.x before 2.4.18 allows local users to execute arbitrary commands via carriage returns in a filename.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fvwm | Fvwm | * | 2.4.17 (including) |
Fvwm | Fvwm | * | 2.5.8 (including) |