CVE-2023-46300: Critical severity iterm2 vulnerability
Published Oct 22, 2023
·Updated
iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to tmux integration.
Affected Software
1 affected component
iTerm2 iTerm2<3.4.20
Remediation
Event History
Oct 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-46300.
2
What is the severity of CVE-2023-46300?
The severity of CVE-2023-46300 is critical with a CVSS score of 9.8.
3
How does CVE-2023-46300 allow code execution?
CVE-2023-46300 allows (potentially remote) code execution by mishandling certain escape sequences related to tmux integration in iTerm2 before version 3.4.20.
4
Which software versions are affected by CVE-2023-46300?
Versions of iTerm2 up to and excluding 3.4.20 are affected by CVE-2023-46300.
5
How can I mitigate the vulnerability in iTerm2?
To mitigate the vulnerability in iTerm2, update to version 3.4.20 or later.