The terminal_helper_execute function in terminal/terminal.c in Xfce Terminal 0.2.6 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a crafted link, as demonstrated using the Open Link functionality.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Xfce_terminal | Os-cillation | 0.2.6 (including) | 0.2.6 (including) |
Xfce4-terminal | Ubuntu | dapper | * |
Xfce4-terminal | Ubuntu | devel | * |
Xfce4-terminal | Ubuntu | edgy | * |
Xfce4-terminal | Ubuntu | feisty | * |