VDB
CVE-2010-2713
CVE-2010-2713
PUBLISHED
CVSS 6.800000190734863 MEDIUM
The vte_sequence_handler_window_manipulation function in vteseq.c in libvte (aka libvte9) in VTE 0.25.1 and earlier, as used in gnome-terminal, does not properly handle escape sequences, which allows remote attackers to execute arbitrary commands or obtain potentially sensitive information via a (1) window title or (2) icon title sequence. NOTE: this issue exists because of a CVE-2003-0070 regression.
EPSS 0.87% · 75.6th percentile
Risk Scores
CVSS 2.0
6.800000190734863
EPSS Score
0.87%
75.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| nalin_dahyabhai | vte | 0.11.21, 0.15.0, 0.16.14 |
Timeline
- Aug 5, 2010 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 7, 2023 EPSS Score
References
- USN-962-1 vendor-advisory
- ADV-2010-1839 vdb
- 41716 vdb
- SUSE-SR:2010:014 vendor-advisory
- http://git.gnome.org/browse/vte/commit/?id=8b971a7b2c59902914ecbbc3915c45dd21530a91 url
- https://bugzilla.redhat.com/show_bug.cgi?id=613110 url
- 40635 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2010-2713 advisory