CVE-2023-46321: Critical severity iterm2 vulnerability
iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs. They may have shell metacharacters for a /usr/bin/man command line.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-46321?
CVE-2023-46321 is a vulnerability in iTerm2 before version 3.5.0beta12 that fails to sanitize paths in x-man-page URLs, potentially allowing command injection through shell metacharacters.
What are the affected software versions for CVE-2023-46321?
Versions of iTerm2 prior to 3.5.0beta12, including 3.4.21 and beta versions from 3.5.0-beta1 to 3.5.0-beta9, are affected by CVE-2023-46321.
How do I fix CVE-2023-46321?
To mitigate CVE-2023-46321, update iTerm2 to version 3.5.0beta12 or later, which includes a fix for the vulnerability.
What can happen if I don't address CVE-2023-46321?
Not addressing CVE-2023-46321 could lead to remote code execution, where an attacker could exploit the vulnerability to execute arbitrary commands on the user's system.
Is CVE-2023-46321 a critical vulnerability?
CVE-2023-46321 is considered serious due to the potential for command injection, which could compromise the security of affected systems.