EnderUNIX Hafiye Remote Terminal Escape Sequence Filtering Weakness
BID:11014
Info
EnderUNIX Hafiye Remote Terminal Escape Sequence Filtering Weakness
| Bugtraq ID: | 11014 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 23 2004 12:00AM |
| Updated: | Aug 23 2004 12:00AM |
| Credit: | Discovery of this issue is credited to Serkan Akpolat <[email protected]>. |
| Vulnerable: |
Enderunix Hafiye 1.0 |
| Not Vulnerable: | |
Discussion
EnderUNIX Hafiye Remote Terminal Escape Sequence Filtering Weakness
EnderUNIX Hafiye is affected by a remote terminal escape sequence weakness. This issue is caused by a failure of the application to properly sanitize user-supplied input.
An attacker might leverage this issue to inject terminal escape sequences into data that will be displayed on in a terminal window; if the terminal is vulnerable to escape sequence issues code execution is possible.
EnderUNIX Hafiye is affected by a remote terminal escape sequence weakness. This issue is caused by a failure of the application to properly sanitize user-supplied input.
An attacker might leverage this issue to inject terminal escape sequences into data that will be displayed on in a terminal window; if the terminal is vulnerable to escape sequence issues code execution is possible.
Exploit / POC
EnderUNIX Hafiye Remote Terminal Escape Sequence Filtering Weakness
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
EnderUNIX Hafiye Remote Terminal Escape Sequence Filtering Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
EnderUNIX Hafiye Remote Terminal Escape Sequence Filtering Weakness
References:
References:
- Hafiye Home Page (Enderunix)
- Hafiye-1.0 Terminal Escape Sequence Injection Vulnerability (Serkan Akpolat
)