CVE Vulnerabilities

CVE-2006-5969

Published: Nov 17, 2006 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

CRLF injection vulnerability in the evalFolderLine function in fvwm 2.5.18 and earlier allows local users to execute arbitrary commands via carriage returns in a directory name, which is not properly handled by fvwm-menu-directory, a variant of CVE-2003-1308.

Affected Software

NameVendorStart VersionEnd Version
FvwmFvwm*2.5.18 (including)
FvwmUbuntudapper*
FvwmUbuntudevel*
FvwmUbuntuedgy*
FvwmUbuntufeisty*
FvwmUbuntugutsy*
FvwmUbuntuhardy*
FvwmUbuntuintrepid*
FvwmUbuntujaunty*
FvwmUbuntukarmic*

References