First published: Fri Jan 02 2009(Updated: )
The default configuration of xterm on Debian GNU/Linux sid and possibly Ubuntu enables the allowWindowOps resource, which allows user-assisted attackers to execute arbitrary code or have unspecified other impact via escape sequences.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
invisible-island xterm | =_nil_ | |
Debian GNU/Linux | ||
Ubuntu BusyBox Static |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2006-7236 is classified as high due to its potential to allow arbitrary code execution.
To fix CVE-2006-7236, disable the allowWindowOps resource in the xterm configuration.
CVE-2006-7236 affects xterm running on default configurations on Debian GNU/Linux sid and possibly Ubuntu.
CVE-2006-7236 is not a remote vulnerability; it requires user-assisted actions to be exploited.
CVE-2006-7236 can allow attackers to execute arbitrary code or achieve other unspecified impacts.