CVE-2024-38396: Code Injection
An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in combination with the built-in tmux integration feature (enabled by default), allows an attacker to inject arbitrary code into the terminal, a different vulnerability than CVE-2024-38395.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38396?
CVE-2024-38396 has been rated with a high severity due to its potential to allow arbitrary code execution.
How do I fix CVE-2024-38396?
To mitigate CVE-2024-38396, update iTerm2 to version 3.5.2 or later, which addresses the vulnerability.
What vulnerabilities are related to CVE-2024-38396?
CVE-2024-38396 is distinct but can be related to other vulnerabilities involving escape sequences and code injection.
Which versions of iTerm2 are affected by CVE-2024-38396?
iTerm2 versions prior to 3.5.2 are affected by CVE-2024-38396.
Can CVE-2024-38396 be exploited remotely?
Yes, CVE-2024-38396 can be exploited remotely if a user interacts with a malicious escape sequence in the terminal.