xterm DECRQSS Remote Command Execution Vulnerability
BID:33060
Info
xterm DECRQSS Remote Command Execution Vulnerability
| Bugtraq ID: | 33060 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2383 CVE-2006-7236 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 28 2008 12:00AM |
| Updated: | Apr 13 2015 10:08PM |
| Credit: | Paul Szabo |
| Vulnerable: |
X.org xterm patch 237 Ubuntu Ubuntu Linux 8.10 sparc Ubuntu Ubuntu Linux 8.10 powerpc Ubuntu Ubuntu Linux 8.10 lpia Ubuntu Ubuntu Linux 8.10 i386 Ubuntu Ubuntu Linux 8.10 amd64 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 lpia Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 10 SP2 SuSE Suse Linux Enterprise Desktop 10 SP2 SuSE Linux 5.0 Sun OpenSolaris build snv_99 Sun OpenSolaris build snv_96 Sun OpenSolaris build snv_95 Sun OpenSolaris build snv_92 Sun OpenSolaris build snv_91 Sun OpenSolaris build snv_106 Sun OpenSolaris build snv_105 Sun OpenSolaris build snv_104 Sun OpenSolaris build snv_103 Sun OpenSolaris build snv_102 Sun OpenSolaris build snv_101a Sun OpenSolaris build snv_101 Sun OpenSolaris build snv_100 Slackware Linux 12.2 Slackware Linux 12.1 Slackware Linux 12.0 Slackware Linux -current S.u.S.E. openSUSE 11.0 S.u.S.E. openSUSE 10.3 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux Desktop 9.0 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Enterprise Linux 5 Server Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 Mandriva Linux Mandrake 2009.0 x86_64 Mandriva Linux Mandrake 2009.0 Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Avaya Messaging Storage Server MM3.0 Avaya Messaging Storage Server 4.0 Avaya Messaging Storage Server 3.1 Avaya Messaging Storage Server 2.0 Avaya Messaging Storage Server 1.0 Avaya Messaging Storage Server Avaya Message Networking MN 3.1 Avaya Message Networking 3.1 Avaya Message Networking Avaya Intuity AUDIX LX 2.0 Avaya Intuity AUDIX LX 1.0 Apple Mac OS X Server 10.5.6 Apple Mac OS X Server 10.5.5 Apple Mac OS X Server 10.5.4 Apple Mac OS X Server 10.5.3 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.6 Apple Mac OS X 10.5.5 Apple Mac OS X 10.5.4 Apple Mac OS X 10.5.3 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.5 |
| Not Vulnerable: |
Apple Mac OS X Server 10.5.7 Apple Mac OS X 10.5.7 |
Discussion
xterm DECRQSS Remote Command Execution Vulnerability
The 'xterm' program is prone to a remote command-execution vulnerability because it fails to sufficiently validate user input.
Successfully exploiting this issue would allow an attacker to execute arbitrary commands on an affected computer in the context of the affected application.
The issue affects xterm with patch 237; other versions may also be affected.
The 'xterm' program is prone to a remote command-execution vulnerability because it fails to sufficiently validate user input.
Successfully exploiting this issue would allow an attacker to execute arbitrary commands on an affected computer in the context of the affected application.
The issue affects xterm with patch 237; other versions may also be affected.
Exploit / POC
xterm DECRQSS Remote Command Execution Vulnerability
An attacker may exploit this issue using readily available commands.
The following example is available:
perl -e 'print "\eP\$q\nwhoami\n\e\\"' > bla.log
cat bla.log
An attacker may exploit this issue using readily available commands.
The following example is available:
perl -e 'print "\eP\$q\nwhoami\n\e\\"' > bla.log
cat bla.log
Solution / Fix
xterm DECRQSS Remote Command Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 7.10 powerpc
Ubuntu Ubuntu Linux 8.04 LTS powerpc
Ubuntu Ubuntu Linux 8.10 powerpc
Ubuntu Ubuntu Linux 8.04 LTS sparc
Ubuntu Ubuntu Linux 6.06 LTS sparc
Mandriva Linux Mandrake 2008.0 x86_64
Ubuntu Ubuntu Linux 8.04 LTS amd64
Mandriva Linux Mandrake 2008.0
Ubuntu Ubuntu Linux 7.10 sparc
Debian Linux 4.0 amd64
Debian Linux 4.0 ia-32
Debian Linux 4.0 hppa
Ubuntu Ubuntu Linux 8.10 sparc
Debian Linux 4.0 mipsel
Mandriva Linux Mandrake 2009.0 x86_64
Ubuntu Ubuntu Linux 8.10 amd64
Debian Linux 4.0 ia-64
Debian Linux 4.0 mips
Mandriva Linux Mandrake 2008.1 x86_64
Debian Linux 4.0 arm
Mandriva Linux Mandrake 2008.1
Debian Linux 4.0 powerpc
Ubuntu Ubuntu Linux 8.10 i386
Ubuntu Ubuntu Linux 6.06 LTS powerpc
Ubuntu Ubuntu Linux 8.04 LTS lpia
Ubuntu Ubuntu Linux 7.10 lpia
Ubuntu Ubuntu Linux 6.06 LTS i386
MandrakeSoft Corporate Server 3.0
MandrakeSoft Corporate Server 3.0 x86_64
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 7.10 powerpc
-
Ubuntu xterm_229-1ubuntu0.1_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/x/xterm/xterm_229-1ubuntu0 .1_powerpc.deb
Ubuntu Ubuntu Linux 8.04 LTS powerpc
-
Ubuntu xterm_229-1ubuntu1.1_powerpc.deb
http://ports.ubuntu.com/pool/main/x/xterm/xterm_229-1ubuntu1.1_powerpc .deb
Ubuntu Ubuntu Linux 8.10 powerpc
-
Ubuntu xterm_235-1ubuntu1.1_powerpc.deb
http://ports.ubuntu.com/pool/main/x/xterm/xterm_235-1ubuntu1.1_powerpc .deb
Ubuntu Ubuntu Linux 8.04 LTS sparc
-
Ubuntu xterm_229-1ubuntu1.1_sparc.deb
http://ports.ubuntu.com/pool/main/x/xterm/xterm_229-1ubuntu1.1_sparc.d eb
Ubuntu Ubuntu Linux 6.06 LTS sparc
-
Ubuntu xterm_208-3.1ubuntu3.1_sparc.deb
http://security.ubuntu.com/ubuntu/pool/main/x/xterm/xterm_208-3.1ubunt u3.1_sparc.deb
Mandriva Linux Mandrake 2008.0 x86_64
-
Mandriva xterm-229-2.1mdv2008.0.x86_64.rpm
http://www.mandriva.com/en/download/
Ubuntu Ubuntu Linux 8.04 LTS amd64
-
Ubuntu xterm_229-1ubuntu1.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/x/xterm/xterm_229-1ubuntu1 .1_amd64.deb
Mandriva Linux Mandrake 2008.0
-
Mandriva xterm-229-2.1mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
Ubuntu Ubuntu Linux 7.10 sparc
-
Ubuntu xterm_229-1ubuntu0.1_sparc.deb
http://security.ubuntu.com/ubuntu/pool/main/x/xterm/xterm_229-1ubuntu0 .1_sparc.deb
Debian Linux 4.0 amd64
-
Debian xterm_222-1etch3_amd64.deb
http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch3_ amd64.deb -
Debian xterm_222-1etch4_amd64.deb
http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch4_ amd64.deb
Debian Linux 4.0 ia-32
-
Debian xterm_222-1etch3_i386.deb
http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch3_ i386.deb -
Debian xterm_222-1etch4_i386.deb
http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch4_ i386.deb
Debian Linux 4.0 hppa
-
Debian xterm_222-1etch3_hppa.deb
http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch3_ hppa.deb -
Debian xterm_222-1etch4_hppa.deb
http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch4_ hppa.deb
Ubuntu Ubuntu Linux 8.10 sparc
-
Ubuntu xterm_235-1ubuntu1.1_sparc.deb
http://ports.ubuntu.com/pool/main/x/xterm/xterm_235-1ubuntu1.1_sparc.d eb
Debian Linux 4.0 mipsel
-
Debian xterm_222-1etch3_mipsel.deb
http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch3_ mipsel.deb -
Debian xterm_222-1etch4_mipsel.deb
http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch4_ mipsel.deb
Mandriva Linux Mandrake 2009.0 x86_64
-
Mandriva xterm-236-1.1mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/
Ubuntu Ubuntu Linux 8.10 amd64
-
Ubuntu xterm_235-1ubuntu1.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/x/xterm/xterm_235-1ubuntu1 .1_amd64.deb
Debian Linux 4.0 ia-64
-
Debian xterm_222-1etch3_ia64.deb
http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch3_ ia64.deb -
Debian xterm_222-1etch4_ia64.deb
http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch4_ ia64.deb
Debian Linux 4.0 mips
-
Debian xterm_222-1etch3_mips.deb
http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch3_ mips.deb -
Debian xterm_222-1etch4_mips.deb
http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch4_ mips.deb
Mandriva Linux Mandrake 2008.1 x86_64
-
Mandriva xterm-232-1.1mdv2008.1.x86_64.rpm
http://www.mandriva.com/en/download/
Debian Linux 4.0 arm
-
Debian xterm_222-1etch3_arm.deb
http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch3_ arm.deb
Mandriva Linux Mandrake 2008.1
-
Mandriva xterm-232-1.1mdv2008.1.i586.rpm
http://www.mandriva.com/en/download/
Debian Linux 4.0 powerpc
-
Debian xterm_222-1etch3_powerpc.deb
http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch3_ powerpc.deb -
Debian xterm_222-1etch4_powerpc.deb
http://security.debian.org/pool/updates/main/x/xterm/xterm_222-1etch4_ powerpc.deb
Ubuntu Ubuntu Linux 8.10 i386
-
Ubuntu xterm_235-1ubuntu1.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/x/xterm/xterm_235-1ubuntu1 .1_i386.deb
Ubuntu Ubuntu Linux 6.06 LTS powerpc
-
Ubuntu xterm_208-3.1ubuntu3.1_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/x/xterm/xterm_208-3.1ubunt u3.1_powerpc.deb
Ubuntu Ubuntu Linux 8.04 LTS lpia
-
Ubuntu xterm_229-1ubuntu1.1_lpia.deb
http://ports.ubuntu.com/pool/main/x/xterm/xterm_229-1ubuntu1.1_lpia.de b
Ubuntu Ubuntu Linux 7.10 lpia
-
Ubuntu xterm_229-1ubuntu0.1_lpia.deb
http://ports.ubuntu.com/pool/main/x/xterm/xterm_229-1ubuntu0.1_lpia.de b
Ubuntu Ubuntu Linux 6.06 LTS i386
-
Ubuntu xterm_208-3.1ubuntu3.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/x/xterm/xterm_208-3.1ubunt u3.1_i386.deb
MandrakeSoft Corporate Server 3.0
-
Mandriva xterm-184-1.1.C30mdk.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 3.0 x86_64
-
Mandriva xterm-184-1.1.C30mdk.x86_64.rpm
http://www.mandriva.com/en/download/
References
xterm DECRQSS Remote Command Execution Vulnerability
References:
References: