HIGH · 7.5

CVE-2003-0064

The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user ...

Vulnerability Description

The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
SgiIrix5.0
HpHp-Ux10.20
IbmAix4.3
SunSolaris2.5.1
SunSunos-

References

FAQ

What is CVE-2003-0064?

CVE-2003-0064 is a vulnerability with a CVSS score of 7.5 (HIGH). The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user ...

How severe is CVE-2003-0064?

CVE-2003-0064 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2003-0064?

Check the references section above for vendor advisories and patch information. Affected products include: Sgi Irix, Hp Hp-Ux, Ibm Aix, Sun Solaris, Sun Sunos.