First published: Fri Jul 09 2010(Updated: )
It was reported to Ubuntu that vte regressed the fix for <a href="https://access.redhat.com/security/cve/CVE-2003-0070">CVE-2003-0070</a> in the following upstream commit: <a href="http://git.gnome.org/browse/vte/commit/?id=58bc3a942f198a1a8788553ca72c19d7c1702b74">http://git.gnome.org/browse/vte/commit/?id=58bc3a942f198a1a8788553ca72c19d7c1702b74</a> This would allow for an information disclosure of the window title of the gnome-terminal. This issue does not affect Red Hat Enterprise Linux 5 or earlier, which still replace the contents of the window title with "LTerminal", rather than "l[contents of terminal window]"; as demonstrated with: $ echo -e "\e[21t"
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nalin Dahyabhai Vte | <=0.25.1 | |
Nalin Dahyabhai Vte | =0.11.21 | |
Nalin Dahyabhai Vte | =0.12.2 | |
Nalin Dahyabhai Vte | =0.14.2 | |
Nalin Dahyabhai Vte | =0.15.0 | |
Nalin Dahyabhai Vte | =0.16.14 | |
Nalin Dahyabhai Vte | =0.17.4 | |
Nalin Dahyabhai Vte | =0.20.5 | |
Nalin Dahyabhai Vte | =0.22.5 | |
Nalin Dahyabhai Vte | =0.24.3 | |
Gnome Gnome-terminal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.