// For flags

CVE-2010-2713

 

Severity Score

6.8
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The vte_sequence_handler_window_manipulation function in vteseq.c in libvte (aka libvte9) in VTE 0.25.1 and earlier, as used in gnome-terminal, does not properly handle escape sequences, which allows remote attackers to execute arbitrary commands or obtain potentially sensitive information via a (1) window title or (2) icon title sequence. NOTE: this issue exists because of a CVE-2003-0070 regression.

La función vte_sequence_handler_window_manipulation en vteseq.c en libvte (conocido como libvte9) de VTE v0.25.1 y anteriores, tal como se utiliza en gnome-terminal, no gestiona adecuadamente las secuencias de escape, lo cual permite a atacantes remotos ejecutar comandos a su elección u obtener información potencialmente sensible a través de un (1) titulo de ventana o (2) icono de secuencia del título. NOTA: esta vulnerabilidad está provocada por una regresión del CVE-2003-0070.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2010-07-13 CVE Reserved
  • 2010-07-16 CVE Published
  • 2024-02-14 EPSS Updated
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Nalin Dahyabhai
Search vendor "Nalin Dahyabhai"
Vte
Search vendor "Nalin Dahyabhai" for product "Vte"
<= 0.25.1
Search vendor "Nalin Dahyabhai" for product "Vte" and version " <= 0.25.1"
-
Affected
in Gnome
Search vendor "Gnome"
Gnome-terminal
Search vendor "Gnome" for product "Gnome-terminal"
*-
Safe
Nalin Dahyabhai
Search vendor "Nalin Dahyabhai"
Vte
Search vendor "Nalin Dahyabhai" for product "Vte"
0.11.21
Search vendor "Nalin Dahyabhai" for product "Vte" and version "0.11.21"
-
Affected
in Gnome
Search vendor "Gnome"
Gnome-terminal
Search vendor "Gnome" for product "Gnome-terminal"
*-
Safe
Nalin Dahyabhai
Search vendor "Nalin Dahyabhai"
Vte
Search vendor "Nalin Dahyabhai" for product "Vte"
0.12.2
Search vendor "Nalin Dahyabhai" for product "Vte" and version "0.12.2"
-
Affected
in Gnome
Search vendor "Gnome"
Gnome-terminal
Search vendor "Gnome" for product "Gnome-terminal"
*-
Safe
Nalin Dahyabhai
Search vendor "Nalin Dahyabhai"
Vte
Search vendor "Nalin Dahyabhai" for product "Vte"
0.14.2
Search vendor "Nalin Dahyabhai" for product "Vte" and version "0.14.2"
-
Affected
in Gnome
Search vendor "Gnome"
Gnome-terminal
Search vendor "Gnome" for product "Gnome-terminal"
*-
Safe
Nalin Dahyabhai
Search vendor "Nalin Dahyabhai"
Vte
Search vendor "Nalin Dahyabhai" for product "Vte"
0.15.0
Search vendor "Nalin Dahyabhai" for product "Vte" and version "0.15.0"
-
Affected
in Gnome
Search vendor "Gnome"
Gnome-terminal
Search vendor "Gnome" for product "Gnome-terminal"
*-
Safe
Nalin Dahyabhai
Search vendor "Nalin Dahyabhai"
Vte
Search vendor "Nalin Dahyabhai" for product "Vte"
0.16.14
Search vendor "Nalin Dahyabhai" for product "Vte" and version "0.16.14"
-
Affected
in Gnome
Search vendor "Gnome"
Gnome-terminal
Search vendor "Gnome" for product "Gnome-terminal"
*-
Safe
Nalin Dahyabhai
Search vendor "Nalin Dahyabhai"
Vte
Search vendor "Nalin Dahyabhai" for product "Vte"
0.17.4
Search vendor "Nalin Dahyabhai" for product "Vte" and version "0.17.4"
-
Affected
in Gnome
Search vendor "Gnome"
Gnome-terminal
Search vendor "Gnome" for product "Gnome-terminal"
*-
Safe
Nalin Dahyabhai
Search vendor "Nalin Dahyabhai"
Vte
Search vendor "Nalin Dahyabhai" for product "Vte"
0.20.5
Search vendor "Nalin Dahyabhai" for product "Vte" and version "0.20.5"
-
Affected
in Gnome
Search vendor "Gnome"
Gnome-terminal
Search vendor "Gnome" for product "Gnome-terminal"
*-
Safe
Nalin Dahyabhai
Search vendor "Nalin Dahyabhai"
Vte
Search vendor "Nalin Dahyabhai" for product "Vte"
0.22.5
Search vendor "Nalin Dahyabhai" for product "Vte" and version "0.22.5"
-
Affected
in Gnome
Search vendor "Gnome"
Gnome-terminal
Search vendor "Gnome" for product "Gnome-terminal"
*-
Safe
Nalin Dahyabhai
Search vendor "Nalin Dahyabhai"
Vte
Search vendor "Nalin Dahyabhai" for product "Vte"
0.24.3
Search vendor "Nalin Dahyabhai" for product "Vte" and version "0.24.3"
-
Affected
in Gnome
Search vendor "Gnome"
Gnome-terminal
Search vendor "Gnome" for product "Gnome-terminal"
*-
Safe