-------- Forwarded Message --------
Subject: [oss-security] Re: CVE request: Escape Sequence Command
Execution vulnerability in Terminology 0.7
Date: Mon, 7 Nov 2016 01:25:23 -0500
From: [email protected]
Reply-To: [email protected]
To: [email protected]
CC: [email protected], [email protected],
[email protected], [email protected]

> Terminology 0.7.0 suffers from a bug similar to CVE-2003-0063, where an
> attacker able to print character escape sequences can modify the window
> title and then insert it back in the terminal's input buffer, resulting
> in arbitrary terminal input, including code execution as a local user.

> https://git.enlightenment.org/apps/terminology.git/commit/?id=b80bedc7c21ecffe99d8d142930db696eebdd6a5
>> src/bin/termptyesc.c

Use CVE-2015-8971.


Attachment: signature.asc
Description: OpenPGP digital signature

------------------------------------------------------------------------------
Developer Access Program for Intel Xeon Phi Processors
Access to Intel Xeon Phi processor-based developer platforms.
With one year of Intel Parallel Studio XE.
Training and support from Colfax.
Order your platform today. http://sdm.link/xeonphi
_______________________________________________
enlightenment-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/enlightenment-devel

Reply via email to