CVE-2003-0066: High severity rxvt rxvt vulnerability
The rxvt terminal emulator 2.7.8 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0066?
CVE-2003-0066 is considered a moderate severity vulnerability due to its potential for exploiting user sessions.
How do I fix CVE-2003-0066?
To fix CVE-2003-0066, users should upgrade to a version of rxvt later than 2.7.8.
What are the affected versions in CVE-2003-0066?
CVE-2003-0066 affects rxvt terminal emulator versions 2.7.8 and earlier.
What is the impact of CVE-2003-0066?
The impact of CVE-2003-0066 allows attackers to manipulate the window title and potentially inject commands into the terminal.
Is CVE-2003-0066 still a risk today?
While CVE-2003-0066 was a risk in the past, its relevance today depends on the usage of outdated versions of rxvt.