CVE-2003-0064: High severity SGI IRIX vulnerability
The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0064?
CVE-2003-0064 has been classified as a medium severity vulnerability.
How do I fix CVE-2003-0064?
To fix CVE-2003-0064, it is recommended to update the dtterm terminal emulator to a secure version provided by the vendor.
Which systems are affected by CVE-2003-0064?
CVE-2003-0064 affects multiple versions of the SGI IRIX and IBM AIX operating systems.
What type of attack is possible with CVE-2003-0064?
An attacker can exploit CVE-2003-0064 to manipulate the terminal window title and potentially execute arbitrary commands.
Are there any workarounds for CVE-2003-0064?
One possible workaround for CVE-2003-0064 is to disable the use of certain escape sequences in terminal settings.