https://seclists.org/oss-sec/2024/q2/289: iTerm2 3.5.x title porting bug
Published Jun 15, 2024
·Updated
Affected Software
1 affected component
iTerm2 iTerm2>=3.5.0<=3.5.1
Frequently Asked Questions
1
Which releases are affected, and which release fixes the issue?
iTerm2 3.5.0 and 3.5.1 are affected, along with some beta versions. The issue is fixed in iTerm2 3.5.2.
2
How can I determine whether an installation is vulnerable?
Run: printf '\e]0;ivulnerable\a\e[21t'. If some or all of the string "vulnerable," other than only the letter "l," appears in the input buffer, the installation is vulnerable.
3
Does disabling title reporting in preferences mitigate the issue?
No. In affected versions, the title-reporting preference is not respected and title reporting remains enabled.
4
How practical is exploitation?
The issue is not considered trivially exploitable without user interaction because a newline or control characters cannot be echoed back. However, it should be treated as potential remote code execution, particularly given possible techniques involving the default macOS Zsh shell.