MEDIUM · 6.8

CVE-2010-2713

The vte_sequence_handler_window_manipulation function in vteseq.c in libvte (aka libvte9) in VTE 0.25.1 and earlier, as used in gnome-terminal, does not properly handle escape sequences, which allows ...

Vulnerability Description

The vte_sequence_handler_window_manipulation function in vteseq.c in libvte (aka libvte9) in VTE 0.25.1 and earlier, as used in gnome-terminal, does not properly handle escape sequences, which allows remote attackers to execute arbitrary commands or obtain potentially sensitive information via a (1) window title or (2) icon title sequence. NOTE: this issue exists because of a CVE-2003-0070 regression.

CVSS Score

6.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Nalin DahyabhaiVte<= 0.25.1
GnomeGnome-TerminalAll versions

References

FAQ

What is CVE-2010-2713?

CVE-2010-2713 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The vte_sequence_handler_window_manipulation function in vteseq.c in libvte (aka libvte9) in VTE 0.25.1 and earlier, as used in gnome-terminal, does not properly handle escape sequences, which allows ...

How severe is CVE-2010-2713?

CVE-2010-2713 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-2713?

Check the references section above for vendor advisories and patch information. Affected products include: Nalin Dahyabhai Vte, Gnome Gnome-Terminal.