Hanterm-XF Window Title Reporting Escape Sequence Command Execution Vulnerability
BID:6946
Info
Hanterm-XF Window Title Reporting Escape Sequence Command Execution Vulnerability
| Bugtraq ID: | 6946 |
| Class: | Design Error |
| CVE: |
CVE-2003-0077 CVE-2003-0077 |
| Remote: | No |
| Local: | No |
| Published: | Feb 25 2003 12:00AM |
| Updated: | Mar 19 2015 09:32AM |
| Credit: | Discovery of these issues is credited to H D Moore and Digital Defense. |
| Vulnerable: |
RedHat hanterm-xf-p19-15.ia64.rpm RedHat hanterm-xf-p19-15.i386.rpm RedHat hanterm-xf-2.0.0-6.i386.rpm RedHat Enterprise Linux WS 2.1 RedHat Enterprise Linux ES 2.1 Red Hat Enterprise Linux AS 2.1 IA64 Red Hat Enterprise Linux AS 2.1 Hanterm hanterm-xf 2.0 |
| Not Vulnerable: |
RedHat hanterm-xf-2.0.5-5.8.0.i386.rpm RedHat hanterm-xf-2.0.5-5.7.4.ia64.rpm RedHat hanterm-xf-2.0.5-5.7.4.i386.rpm |
Discussion
Hanterm-XF Window Title Reporting Escape Sequence Command Execution Vulnerability
Hanterm-XF's window title reporting feature may be abused to execute arbitrary commands on the system running the vulnerable terminal emulator. The terminal software supports escape sequences which can change the title of a terminal window and then report the title back to the command line. In this manner, an attacker can inject malicious escape sequences which include arbitrary commands in the terminal window title and then cause the commands to be displayed on the command line.
It is possible to exploit these issues if an attacker can cause malicious escape sequences to be displayed in a terminal window of a vulnerable terminal emulator. Exploitation will still require the user to press 'Enter' once the malicious commands are dumped from the window title to the command line. Other emulator features may be used to obfuscate the attack and trick the user into pressing 'Enter'.
Hanterm-XF's window title reporting feature may be abused to execute arbitrary commands on the system running the vulnerable terminal emulator. The terminal software supports escape sequences which can change the title of a terminal window and then report the title back to the command line. In this manner, an attacker can inject malicious escape sequences which include arbitrary commands in the terminal window title and then cause the commands to be displayed on the command line.
It is possible to exploit these issues if an attacker can cause malicious escape sequences to be displayed in a terminal window of a vulnerable terminal emulator. Exploitation will still require the user to press 'Enter' once the malicious commands are dumped from the window title to the command line. Other emulator features may be used to obfuscate the attack and trick the user into pressing 'Enter'.
Exploit / POC
Hanterm-XF Window Title Reporting Escape Sequence Command Execution Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Hanterm-XF Window Title Reporting Escape Sequence Command Execution Vulnerability
Solution:
Red Hat has released advisory RHSA-2003:070-01 with fixes to address this issue. Red Hat Enterprise Linux updates are available via the Red Hat Network.
RedHat hanterm-xf-p19-15.ia64.rpm
RedHat hanterm-xf-2.0.0-6.i386.rpm
RedHat hanterm-xf-p19-15.i386.rpm
Solution:
Red Hat has released advisory RHSA-2003:070-01 with fixes to address this issue. Red Hat Enterprise Linux updates are available via the Red Hat Network.
RedHat hanterm-xf-p19-15.ia64.rpm
-
RedHat hanterm-xf-2.0.5-5.7.4.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/hanterm-xf-2.0.5-5.7.4.ia64.rp m
RedHat hanterm-xf-2.0.0-6.i386.rpm
-
RedHat hanterm-xf-2.0.5-5.8.0.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/hanterm-xf-2.0.5-5.8.0.i386.rp m
RedHat hanterm-xf-p19-15.i386.rpm
-
RedHat hanterm-xf-2.0.5-5.7.4.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/hanterm-xf-2.0.5-5.7.4.i386.rp m
References
Hanterm-XF Window Title Reporting Escape Sequence Command Execution Vulnerability
References:
References:
- RHSA-2003:071-12 Updated Hangul Terminal packages provide security fixes (Red Hat)
- TERMINAL EMULATOR SECURITY ISSUES (Digital Defense)
- Terminal Emulator Security Issues (H D Moore
)