-------- Forwarded Message -------- Subject: [oss-security] Re: CVE request: Escape Sequence Command Execution vulnerability in Terminology 0.7 Date: Mon, 7 Nov 2016 01:25:23 -0500 From: [email protected] Reply-To: [email protected] To: [email protected] CC: [email protected], [email protected], [email protected], [email protected] > Terminology 0.7.0 suffers from a bug similar to CVE-2003-0063, where an > attacker able to print character escape sequences can modify the window > title and then insert it back in the terminal's input buffer, resulting > in arbitrary terminal input, including code execution as a local user. > https://git.enlightenment.org/apps/terminology.git/commit/?id=b80bedc7c21ecffe99d8d142930db696eebdd6a5 >> src/bin/termptyesc.c Use CVE-2015-8971.
signature.asc
Description: OpenPGP digital signature
------------------------------------------------------------------------------ Developer Access Program for Intel Xeon Phi Processors Access to Intel Xeon Phi processor-based developer platforms. With one year of Intel Parallel Studio XE. Training and support from Colfax. Order your platform today. http://sdm.link/xeonphi
_______________________________________________ enlightenment-devel mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/enlightenment-devel
