Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
0

CVE-2003-0070

Disclosure Date: March 03, 2003
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

VTE, as used by default in gnome-terminal terminal emulator 2.2 and as an option in gnome-terminal 2.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user’s terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
None
Impact Score:
Unknown
Exploitability Score:
Unknown
Vector:
Unknown
Attack Vector (AV):
Unknown
Attack Complexity (AC):
Unknown
Privileges Required (PR):
Unknown
User Interaction (UI):
Unknown
Scope (S):
Unknown
Confidentiality (C):
Unknown
Integrity (I):
Unknown
Availability (A):
Unknown

General Information

Vendors

  • gnome,
  • nalin dahyabhai

Products

  • gnome-terminal 2.0,
  • gnome-terminal 2.2,
  • vte 0.11.21,
  • vte 0.12.2,
  • vte 0.14.2,
  • vte 0.15.0,
  • vte 0.16.14,
  • vte 0.17.4,
  • vte 0.20.5,
  • vte 0.22.5,
  • vte 0.24.3,
  • vte 0.25.1
Technical Analysis