6.8

CVE-2010-2713

Exploit

The vte_sequence_handler_window_manipulation function in vteseq.c in libvte (aka libvte9) in VTE 0.25.1 and earlier, as used in gnome-terminal, does not properly handle escape sequences, which allows remote attackers to execute arbitrary commands or obtain potentially sensitive information via a (1) window title or (2) icon title sequence.  NOTE: this issue exists because of a CVE-2003-0070 regression.

Data is provided by the National Vulnerability Database (NVD)
Nalin DahyabhaiVte Version <= 0.25.1
Nalin DahyabhaiVte Version0.11.21
Nalin DahyabhaiVte Version0.12.2
Nalin DahyabhaiVte Version0.14.2
Nalin DahyabhaiVte Version0.15.0
Nalin DahyabhaiVte Version0.16.14
Nalin DahyabhaiVte Version0.17.4
Nalin DahyabhaiVte Version0.20.5
Nalin DahyabhaiVte Version0.22.5
Nalin DahyabhaiVte Version0.24.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.76% 0.71
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P