Bug 479000 - CVE-2008-2383 xterm: arbitrary command injection
Summary: CVE-2008-2383 xterm: arbitrary command injection
Keywords:
Status: CLOSED NEXTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: xterm
Version: 10
Hardware: All
OS: Linux
urgent
urgent
Target Milestone: ---
Assignee: Miroslav Lichvar
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2009-01-06 12:53 UTC by Christoph Höger
Modified: 2009-01-07 09:24 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2009-01-07 09:12:11 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Christoph Höger 2009-01-06 12:53:33 UTC
Description of problem:
xterm has a security hole that allows attackes to modify files that are displayed in xterm in a way that causes xterm to execute arbitrary commands

Version-Release number of selected component (if applicable):
xterm-237-1.fc10.i386

How reproducible:
always

Steps to Reproduce:
1.  open xterm
2.  perl -e 'print "\eP\$q\nwhoami\n\e\\"' > bla.log
3.  cat bla.log

  
Actual results:
whoami is executed

Expected results:
that should not happen

Additional info:
see
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=510030
there seems to be a patch

Comment 1 Fedora Update System 2009-01-06 14:35:18 UTC
xterm-238-1.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/xterm-238-1.fc10

Comment 2 Fedora Update System 2009-01-06 14:36:55 UTC
xterm-238-1.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/xterm-238-1.fc9

Comment 3 Fedora Update System 2009-01-06 14:38:05 UTC
xterm-238-1.fc8 has been submitted as an update for Fedora 8.
http://admin.fedoraproject.org/updates/xterm-238-1.fc8

Comment 4 Fedora Update System 2009-01-07 09:12:09 UTC
xterm-238-1.fc9 has been pushed to the Fedora 9 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 5 Fedora Update System 2009-01-07 09:16:46 UTC
xterm-238-1.fc10 has been pushed to the Fedora 10 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 6 Fedora Update System 2009-01-07 09:24:57 UTC
xterm-238-1.fc8 has been pushed to the Fedora 8 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.