Vulnerability Description
xterm before 380 supports ReGIS reporting for character-set names even if they have unexpected characters (i.e., neither alphanumeric nor underscore), aka a pointer/overflow issue. This can only occur for xterm installations that are configured at compile time to use a certain experimental feature.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Invisible-Island | Xterm | < 380 |
References
- https://invisible-island.net/xterm/xterm.log.html#xterm_380Release Notes
- https://invisible-island.net/xterm/xterm.log.html#xterm_380Release Notes
FAQ
What is CVE-2023-40359?
CVE-2023-40359 is a vulnerability with a CVSS score of 9.8 (CRITICAL). xterm before 380 supports ReGIS reporting for character-set names even if they have unexpected characters (i.e., neither alphanumeric nor underscore), aka a pointer/overflow issue. This can only occur...
How severe is CVE-2023-40359?
CVE-2023-40359 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-40359?
Check the references section above for vendor advisories and patch information. Affected products include: Invisible-Island Xterm.