CVE-2006-7236: Critical severity invisible-island xterm vulnerability
Published Jan 2, 2009
·Updated
The default configuration of xterm on Debian GNU/Linux sid and possibly Ubuntu enables the allowWindowOps resource, which allows user-assisted attackers to execute arbitrary code or have unspecified other impact via escape sequences.
Affected Software
3 affected components
invisible-island xterm=_nil_
Debian Debian Linux
Ubuntu Linux
Event History
Jan 2, 2009
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
06:11 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2006-7236?
The severity of CVE-2006-7236 is classified as high due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2006-7236?
To fix CVE-2006-7236, disable the allowWindowOps resource in the xterm configuration.
3
Which versions of xterm are affected by CVE-2006-7236?
CVE-2006-7236 affects xterm running on default configurations on Debian GNU/Linux sid and possibly Ubuntu.
4
Is CVE-2006-7236 a remote vulnerability?
CVE-2006-7236 is not a remote vulnerability; it requires user-assisted actions to be exploited.
5
What impact can CVE-2006-7236 have?
CVE-2006-7236 can allow attackers to execute arbitrary code or achieve other unspecified impacts.