First published: Fri Jul 09 2010(Updated: )
It was reported to Ubuntu that vte regressed the fix for <a href="https://access.redhat.com/security/cve/CVE-2003-0070">CVE-2003-0070</a> in the following upstream commit: <a href="http://git.gnome.org/browse/vte/commit/?id=58bc3a942f198a1a8788553ca72c19d7c1702b74">http://git.gnome.org/browse/vte/commit/?id=58bc3a942f198a1a8788553ca72c19d7c1702b74</a> This would allow for an information disclosure of the window title of the gnome-terminal. This issue does not affect Red Hat Enterprise Linux 5 or earlier, which still replace the contents of the window title with "LTerminal", rather than "l[contents of terminal window]"; as demonstrated with: $ echo -e "\e[21t"
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
GNOME VTE | <=0.25.1 | |
GNOME VTE | =0.11.21 | |
GNOME VTE | =0.12.2 | |
GNOME VTE | =0.14.2 | |
GNOME VTE | =0.15.0 | |
GNOME VTE | =0.16.14 | |
GNOME VTE | =0.17.4 | |
GNOME VTE | =0.20.5 | |
GNOME VTE | =0.22.5 | |
GNOME VTE | =0.24.3 | |
GNOME Terminal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2713 is considered a moderate severity vulnerability due to its potential impact on system stability and security.
To remediate CVE-2010-2713, users should upgrade to a patched version of vte that is above 0.25.1.
CVE-2010-2713 affects several vte versions including 0.11.21, 0.12.2, 0.14.2, 0.15.0, 0.16.14, 0.17.4, 0.20.5, 0.22.5, and 0.24.3.
CVE-2010-2713 represents a regression of a previously fixed issue, which may lead to incorrect handling of input.
No, GNOME Terminal itself is not listed as vulnerable to CVE-2010-2713.