CVE-2010-2713: Medium severity gnome vte vulnerability
It was reported to Ubuntu that vte regressed the fix for CVE-2003-0070 in the following upstream commit:
http://git.gnome.org/browse/vte/commit/?id=58bc3a942f198a1a8788553ca72c19d7c1702b74
This would allow for an information disclosure of the window title of the gnome-terminal.
This issue does not affect Red Hat Enterprise Linux 5 or earlier, which still replace the contents of the window title with "LTerminal", rather than "l[contents of terminal window]"; as demonstrated with:
$ echo -e "\e[21t"
Other sources
The vtesequencehandlerwindowmanipulation function in vteseq.c in libvte (aka libvte9) in VTE 0.25.1 and earlier, as used in gnome-terminal, does not properly handle escape sequences, which allows remote attackers to execute arbitrary commands or obtain potentially sensitive information via a (1) window title or (2) icon title sequence. NOTE: this issue exists because of a CVE-2003-0070 regression.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2713?
CVE-2010-2713 is considered a moderate severity vulnerability due to its potential impact on system stability and security.
How do I fix CVE-2010-2713?
To remediate CVE-2010-2713, users should upgrade to a patched version of vte that is above 0.25.1.
Which versions of GNOME VTE are affected by CVE-2010-2713?
CVE-2010-2713 affects several vte versions including 0.11.21, 0.12.2, 0.14.2, 0.15.0, 0.16.14, 0.17.4, 0.20.5, 0.22.5, and 0.24.3.
What is the nature of the vulnerability in CVE-2010-2713?
CVE-2010-2713 represents a regression of a previously fixed issue, which may lead to incorrect handling of input.
Is GNOME Terminal vulnerable to CVE-2010-2713?
No, GNOME Terminal itself is not listed as vulnerable to CVE-2010-2713.