Xfce-Terminal Remote Command Injection Vulnerability
BID:24889
Info
Xfce-Terminal Remote Command Injection Vulnerability
| Bugtraq ID: | 24889 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3770 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 12 2007 12:00AM |
| Updated: | Oct 25 2007 02:56PM |
| Credit: | Lasse Kärkkäinen is credited with the discovery of this issue. |
| Vulnerable: |
Xfce Xfce-Terminal 0.2.6 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: | |
Discussion
Xfce-Terminal Remote Command Injection Vulnerability
Xfce Terminal is prone to a remote command-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Attackers can exploit this issue to execute arbitrary commands in the context of the application, facilitating the remote compromise of affected computers.
Xfce Terminal 0.2.6 is vulnerable; other versions may also be affected.
Xfce Terminal is prone to a remote command-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Attackers can exploit this issue to execute arbitrary commands in the context of the application, facilitating the remote compromise of affected computers.
Xfce Terminal 0.2.6 is vulnerable; other versions may also be affected.
Exploit / POC
Xfce-Terminal Remote Command Injection Vulnerability
Attackers entice victim users to open a malicious URI.
Attackers entice victim users to open a malicious URI.
Solution / Fix
Xfce-Terminal Remote Command Injection Vulnerability
Solution:
Please see the referenced advisories for more information.
Solution:
Please see the referenced advisories for more information.
References
Xfce-Terminal Remote Command Injection Vulnerability
References:
References: