CVE Vulnerabilities

CVE-2007-3770

Published: Jul 15, 2007 | Modified: Jul 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:M/Au:N/C:C/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The terminal_helper_execute function in terminal/terminal.c in Xfce Terminal 0.2.6 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a crafted link, as demonstrated using the Open Link functionality.

Affected Software

Name Vendor Start Version End Version
Xfce_terminal Os-cillation 0.2.6 (including) 0.2.6 (including)
Xfce4-terminal Ubuntu dapper *
Xfce4-terminal Ubuntu devel *
Xfce4-terminal Ubuntu edgy *
Xfce4-terminal Ubuntu feisty *

References