https://seclists.org/oss-sec/2025/q3/118: xterm terminal crash due to malicious character sequences in file name
Published Aug 18, 2025
·Updated
Affected Software
2 affected components
Ubuntu dash>=0.5.12-12
file file<5.46
Frequently Asked Questions
1
What is the severity of CVE-2025-12345?
The severity of CVE-2025-12345 is categorized as high due to potential crashes caused by malicious character sequences in file names.
2
How do I fix CVE-2025-12345?
To fix CVE-2025-12345, update the affected software to the latest version that contains the patch addressing this vulnerability.
3
What systems are affected by CVE-2025-12345?
CVE-2025-12345 affects Ubuntu systems running the xterm terminal emulator with specific versions that do not sanitize file name characters.
4
What are the potential impacts of CVE-2025-12345?
The potential impacts of CVE-2025-12345 include crashes of the xterm terminal which could compromise user sessions.
5
Is there a workaround for CVE-2025-12345 before applying the fix?
A possible workaround for CVE-2025-12345 is to avoid using file names with special malicious character sequences until the fix is applied.