RXVT Screen Dump Escape Sequence Local File Corruption Vulnerability
BID:6938
Info
RXVT Screen Dump Escape Sequence Local File Corruption Vulnerability
| Bugtraq ID: | 6938 |
| Class: | Design Error |
| CVE: |
CVE-2003-0022 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 24 2003 12:00AM |
| Updated: | Jul 11 2009 08:06PM |
| Credit: | Discovery of these issues is credited to H D Moore and Digital Defense. |
| Vulnerable: |
rxvt rxvt 2.7.8 rxvt rxvt 2.7.7 rxvt rxvt 2.7.6 rxvt rxvt 2.7.5 rxvt rxvt 2.6.4 rxvt rxvt 2.6.3 rxvt rxvt 2.6.2 rxvt rxvt 2.6.1 |
| Not Vulnerable: |
rxvt rxvt 2.7.10 |
Exploit / POC
RXVT Screen Dump Escape Sequence Local File Corruption Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
RXVT Screen Dump Escape Sequence Local File Corruption Vulnerability
Solution:
Gentoo Linux has released an advisory. Users who have installed x11-terms/rxvt are advised to upgrade to rxvt-2.7.8-r6 by issuing the following commands:
emerge sync
emerge rxvt
emerge clean
Mandrake has released a security advisory (MDKSA-2003:034) which contains fixes for this issue. Users are advised to upgrade as soon as possible.
Fixes available:
rxvt rxvt 2.6.1
rxvt rxvt 2.6.2
rxvt rxvt 2.6.3
rxvt rxvt 2.6.4
rxvt rxvt 2.7.5
rxvt rxvt 2.7.6
rxvt rxvt 2.7.7
rxvt rxvt 2.7.8
Solution:
Gentoo Linux has released an advisory. Users who have installed x11-terms/rxvt are advised to upgrade to rxvt-2.7.8-r6 by issuing the following commands:
emerge sync
emerge rxvt
emerge clean
Mandrake has released a security advisory (MDKSA-2003:034) which contains fixes for this issue. Users are advised to upgrade as soon as possible.
Fixes available:
rxvt rxvt 2.6.1
-
rxvt rxvt-2.7.10.tar.gz
ftp://ftp.rxvt.org/pub/rxvt/rxvt-2.7.10.tar.gz
rxvt rxvt 2.6.2
-
rxvt rxvt-2.7.10.tar.gz
ftp://ftp.rxvt.org/pub/rxvt/rxvt-2.7.10.tar.gz
rxvt rxvt 2.6.3
-
rxvt rxvt-2.7.10.tar.gz
ftp://ftp.rxvt.org/pub/rxvt/rxvt-2.7.10.tar.gz
rxvt rxvt 2.6.4
-
rxvt rxvt-2.7.10.tar.gz
ftp://ftp.rxvt.org/pub/rxvt/rxvt-2.7.10.tar.gz
rxvt rxvt 2.7.5
-
rxvt rxvt-2.7.10.tar.gz
ftp://ftp.rxvt.org/pub/rxvt/rxvt-2.7.10.tar.gz
rxvt rxvt 2.7.6
-
rxvt rxvt-2.7.10.tar.gz
ftp://ftp.rxvt.org/pub/rxvt/rxvt-2.7.10.tar.gz
rxvt rxvt 2.7.7
-
rxvt rxvt-2.7.10.tar.gz
ftp://ftp.rxvt.org/pub/rxvt/rxvt-2.7.10.tar.gz
rxvt rxvt 2.7.8
-
Red Hat rxvt-2.7.8-3.6.2.1.i386.rpm
Red Hat Linux 6.2
ftp://updates.redhat.com/6.2/en/os/i386/rxvt-2.7.8-3.6.2.1.i386.rpm -
Red Hat rxvt-2.7.8-3.6.2.1.src.rpm
Red Hat Linux 6.2
ftp://updates.redhat.com/6.2/en/os/SRPMS/rxvt-2.7.8-3.6.2.1.src.rpm -
Red Hat rxvt-2.7.8-3.7.0.1.i386.rpm
Red Hat Linux 7.0
ftp://updates.redhat.com/7.0/en/os/i386/rxvt-2.7.8-3.7.0.1.i386.rpm -
Red Hat rxvt-2.7.8-3.7.0.1.src.rpm
Red Hat Linux 7.0
ftp://updates.redhat.com/7.0/en/os/SRPMS/rxvt-2.7.8-3.7.0.1.src.rpm -
Red Hat rxvt-2.7.8-3.7.1.1.i386.rpm
Red Hat Linux 7.1
ftp://updates.redhat.com/7.1/en/os/i386/rxvt-2.7.8-3.7.1.1.i386.rpm -
Red Hat rxvt-2.7.8-3.7.1.1.src.rpm
Red Hat Linux 7.1
ftp://updates.redhat.com/7.1/en/os/SRPMS/rxvt-2.7.8-3.7.1.1.src.rpm -
Red Hat rxvt-2.7.8-4.i386.rpm
Red Hat Linux 7.2
ftp://updates.redhat.com/7.2/en/os/i386/rxvt-2.7.8-4.i386.rpm -
Red Hat rxvt-2.7.8-4.i386.rpm
Red Hat Linux 7.3
ftp://updates.redhat.com/7.3/en/os/i386/rxvt-2.7.8-4.i386.rpm -
Red Hat rxvt-2.7.8-4.ia64.rpm
Red Hat Linux 7.2
ftp://updates.redhat.com/7.2/en/os/ia64/rxvt-2.7.8-4.ia64.rpm -
Red Hat rxvt-2.7.8-4.src.rpm
Red Hat Linux 7.2
ftp://updates.redhat.com/7.2/en/os/SRPMS/rxvt-2.7.8-4.src.rpm -
Red Hat rxvt-2.7.8-4.src.rpm
Red Hat Linux 7.3
ftp://updates.redhat.com/7.3/en/os/SRPMS/rxvt-2.7.8-4.src.rpm -
rxvt rxvt-2.7.10.tar.gz
ftp://ftp.rxvt.org/pub/rxvt/rxvt-2.7.10.tar.gz
References
RXVT Screen Dump Escape Sequence Local File Corruption Vulnerability
References:
References:
- TERMINAL EMULATOR SECURITY ISSUES (Digital Defense)
- Re: Terminal Emulator Security Issues (Michael Jennings
) - Re: Terminal Emulator Security Issues (H D Moore
) - Terminal Emulator Security Issues (H D Moore
)