CVE-2006-7236

The default configuration of xterm on Debian GNU/Linux sid and possibly Ubuntu enables the allowWindowOps resource, which allows user-assisted attackers to execute arbitrary code or have unspecified other impact via escape sequences.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:invisible-island:xterm:_nil_:*:*:*:*:*:*:*
OR cpe:2.3:o:debian:debian_linux:*:*:*:*:*:*:*:*
cpe:2.3:o:ubuntu:linux:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:24

Type Values Removed Values Added
References () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=384593 - () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=384593 -
References () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=510030 - () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=510030 -
References () http://secunia.com/advisories/33388 - () http://secunia.com/advisories/33388 -
References () https://usn.ubuntu.com/703-1/ - () https://usn.ubuntu.com/703-1/ -

Information

Published : 2009-01-02 18:11

Updated : 2024-11-21 00:24


NVD link : CVE-2006-7236

Mitre link : CVE-2006-7236

CVE.ORG link : CVE-2006-7236


JSON object : View

Products Affected

ubuntu

  • linux

debian

  • debian_linux

invisible-island

  • xterm
CWE
CWE-16

Configuration