REDHAT-BUG-613110: High severity gnome terminal vulnerability
It was reported to Ubuntu that vte regressed the fix for CVE-2003-0070 in the following upstream commit:
http://git.gnome.org/browse/vte/commit/?id=58bc3a942f198a1a8788553ca72c19d7c1702b74
This would allow for an information disclosure of the window title of the gnome-terminal.
This issue does not affect Red Hat Enterprise Linux 5 or earlier, which still replace the contents of the window title with "LTerminal", rather than "l[contents of terminal window]"; as demonstrated with:
$ echo -e "\e[21t"
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-613110?
REDHAT-BUG-613110 is considered a moderate severity vulnerability impacting GNOME VTE.
How do I fix REDHAT-BUG-613110?
To fix REDHAT-BUG-613110, ensure you update to the latest version of GNOME VTE that addresses this regression.
Which versions of software are affected by REDHAT-BUG-613110?
REDHAT-BUG-613110 affects versions of GNOME VTE prior to the update that resolves the regression.
Is REDHAT-BUG-613110 related to CVE-2003-0070?
Yes, REDHAT-BUG-613110 is a regression of the fix for CVE-2003-0070 in GNOME VTE.
What should I do if I cannot update to fix REDHAT-BUG-613110?
If you cannot update, consider using alternative terminal emulators until a fix is available for REDHAT-BUG-613110.