First published: Fri Jul 09 2010(Updated: )
It was reported to Ubuntu that vte regressed the fix for <a href="https://access.redhat.com/security/cve/CVE-2003-0070">CVE-2003-0070</a> in the following upstream commit: <a href="http://git.gnome.org/browse/vte/commit/?id=58bc3a942f198a1a8788553ca72c19d7c1702b74">http://git.gnome.org/browse/vte/commit/?id=58bc3a942f198a1a8788553ca72c19d7c1702b74</a> This would allow for an information disclosure of the window title of the gnome-terminal. This issue does not affect Red Hat Enterprise Linux 5 or earlier, which still replace the contents of the window title with "LTerminal", rather than "l[contents of terminal window]"; as demonstrated with: $ echo -e "\e[21t"
Affected Software | Affected Version | How to fix |
---|---|---|
GNOME Terminal (VTE) | = |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-613110 is considered a moderate severity vulnerability impacting GNOME VTE.
To fix REDHAT-BUG-613110, ensure you update to the latest version of GNOME VTE that addresses this regression.
REDHAT-BUG-613110 affects versions of GNOME VTE prior to the update that resolves the regression.
Yes, REDHAT-BUG-613110 is a regression of the fix for CVE-2003-0070 in GNOME VTE.
If you cannot update, consider using alternative terminal emulators until a fix is available for REDHAT-BUG-613110.