CVE-2010-2713

N/A Unknown
Published: August 05, 2010 Modified: April 29, 2026
View on NVD

Description

The vte_sequence_handler_window_manipulation function in vteseq.c in libvte (aka libvte9) in VTE 0.25.1 and earlier, as used in gnome-terminal, does not properly handle escape sequences, which allows remote attackers to execute arbitrary commands or obtain potentially sensitive information via a (1) window title or (2) icon title sequence. NOTE: this issue exists because of a CVE-2003-0070 regression.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/40635
Source: security@ubuntu.com
Vendor Advisory
http://www.securityfocus.com/bid/41716
Source: security@ubuntu.com
http://www.ubuntu.com/usn/usn-962-1
Source: security@ubuntu.com
http://www.vupen.com/english/advisories/2010/1839
Source: security@ubuntu.com
Vendor Advisory
http://git.gnome.org/browse/vte/commit/?id=8b971a7b2c59902914ecbbc3915c45dd21530a91
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit Patch
http://secunia.com/advisories/40635
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.securityfocus.com/bid/41716
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/usn-962-1
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2010/1839
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=613110
Source: af854a3a-2127-422b-91ae-364da2661108

14 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
3.3%
87th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

gnome nalin_dahyabhai