https://seclists.org/oss-sec/2025/q1/1: iTerm2 < 3.5.11 logs input/ouput to /tmp/framer.txt on mote host
Published Jan 3, 2025
·Updated
Affected Software
1 affected component
iTerm2 iTerm2<3.5.11
Frequently Asked Questions
1
Which users are exposed to this issue?
Users are affected if they used iTerm2's SSH integration feature in versions 3.5.6 through 3.5.10, or beta versions of 3.5.6 and later. The exposure is on the remote host involved in the SSH connection.
2
Who could access the captured SSH data?
Other users on the remote host may be able to read the logged data if /tmp/framer.txt is readable to them. Whether this is possible depends on the user's umask on that system.
3
How can I check whether a remote host may contain exposed session data?
Check the remote host for /tmp/framer.txt. The affected SSH integration bug logged SSH input and output to that file.
4
What is the available remediation?
Update iTerm2 to version 3.5.11 or later. The release announcement recommends updating immediately.