CVE-2003-0070: Medium severity Nalin Dahyabhai Vte vulnerability
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Other sources
VTE, as used by default in gnome-terminal terminal emulator 2.2 and as an option in gnome-terminal 2.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0070?
CVE-2003-0070 is considered a low severity vulnerability primarily affecting specific versions of GNOME Terminal and VTE.
How do I fix CVE-2003-0070?
To fix CVE-2003-0070, you should update your GNOME Terminal and VTE to a secure version that is not affected by this vulnerability.
What systems are affected by CVE-2003-0070?
CVE-2003-0070 affects GNOME Terminal versions 2.0 and 2.2, as well as several versions of Gnome's VTE.
Can CVE-2003-0070 be exploited remotely?
Yes, CVE-2003-0070 can potentially be exploited remotely if an attacker can manipulate terminal sessions.
Is CVE-2003-0070 still a concern today?
While CVE-2003-0070 is dated, it remains a concern for legacy systems still running the affected software versions.