Lucene search

K
cve[email protected]CVE-2003-0064
HistorySep 01, 2004 - 4:00 a.m.

CVE-2003-0064

2004-09-0104:00:00
web.nvd.nist.gov
20
dtterm
terminal emulator
window title
command execution
cve-2003-0064

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.2 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.4%

The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user’s terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.

Affected configurations

NVD
Node
sgiirixMatch5.0
OR
sgiirixMatch5.0.1
OR
sgiirixMatch5.1
OR
sgiirixMatch5.1.1
OR
sgiirixMatch5.2
OR
sgiirixMatch5.3
OR
sgiirixMatch6.0
OR
sgiirixMatch6.0.1
OR
sgiirixMatch6.1
OR
sgiirixMatch6.2
OR
sgiirixMatch6.3
OR
sgiirixMatch6.4
OR
sgiirixMatch6.5
OR
sgiirixMatch6.5.1
OR
sgiirixMatch6.5.2
OR
sgiirixMatch6.5.2f
OR
sgiirixMatch6.5.2m
OR
sgiirixMatch6.5.3
OR
sgiirixMatch6.5.3f
OR
sgiirixMatch6.5.3m
OR
sgiirixMatch6.5.4
OR
sgiirixMatch6.5.4f
OR
sgiirixMatch6.5.4m
OR
sgiirixMatch6.5.5
OR
sgiirixMatch6.5.5f
OR
sgiirixMatch6.5.5m
OR
sgiirixMatch6.5.6
OR
sgiirixMatch6.5.6f
OR
sgiirixMatch6.5.6m
OR
sgiirixMatch6.5.7
OR
sgiirixMatch6.5.7f
OR
sgiirixMatch6.5.7m
OR
sgiirixMatch6.5.8
OR
sgiirixMatch6.5.8f
OR
sgiirixMatch6.5.8m
OR
sgiirixMatch6.5.9
OR
sgiirixMatch6.5.9f
OR
sgiirixMatch6.5.9m
OR
sgiirixMatch6.5.10
OR
sgiirixMatch6.5.10f
OR
sgiirixMatch6.5.10m
OR
sgiirixMatch6.5.11
OR
sgiirixMatch6.5.11f
OR
sgiirixMatch6.5.11m
OR
sgiirixMatch6.5.12
OR
sgiirixMatch6.5.12f
OR
sgiirixMatch6.5.12m
OR
sgiirixMatch6.5.13
OR
sgiirixMatch6.5.13f
OR
sgiirixMatch6.5.13m
OR
sgiirixMatch6.5.14
OR
sgiirixMatch6.5.14f
OR
sgiirixMatch6.5.14m
OR
sgiirixMatch6.5.15
OR
sgiirixMatch6.5.15f
OR
sgiirixMatch6.5.15m
OR
sgiirixMatch6.5.16
OR
sgiirixMatch6.5.16f
OR
sgiirixMatch6.5.16m
OR
sgiirixMatch6.5.17
OR
sgiirixMatch6.5.17f
OR
sgiirixMatch6.5.17m
OR
sgiirixMatch6.5.18
OR
sgiirixMatch6.5.18f
OR
sgiirixMatch6.5.18m
Node
hphp-uxMatch10.20
OR
hphp-uxMatch10.24
OR
hphp-uxMatch10.26
OR
hphp-uxMatch10.30
OR
hphp-uxMatch10.34
OR
hphp-uxMatch11.00
OR
hphp-uxMatch11.04
OR
hphp-uxMatch11.11
OR
hphp-uxMatch11.20
OR
hphp-uxMatch11.22
OR
ibmaixMatch4.3
OR
ibmaixMatch4.3.1
OR
ibmaixMatch4.3.2
OR
ibmaixMatch4.3.3
OR
ibmaixMatch5.1
OR
ibmaixMatch5.2
OR
sunsolarisMatch2.5.1x86
OR
sunsolarisMatch2.6
OR
sunsolarisMatch7.0x86
OR
sunsolarisMatch8.0x86
OR
sunsolarisMatch9.0sparc
OR
sunsolarisMatch9.0x86
OR
sunsunosMatch-
OR
sunsunosMatch5.5.1
OR
sunsunosMatch5.7
OR
sunsunosMatch5.8

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.2 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.4%

Related for CVE-2003-0064