Lucene search

K
cve[email protected]CVE-2008-2383
HistoryJan 02, 2009 - 6:11 p.m.

CVE-2008-2383

2009-01-0218:11:09
CWE-94
web.nvd.nist.gov
54
crlf injection
xterm
security vulnerability
decrqss
text file
user-assisted attack
command execution

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8 High

AI Score

Confidence

High

0.012 Low

EPSS

Percentile

85.2%

CRLF injection vulnerability in xterm allows user-assisted attackers to execute arbitrary commands via LF (aka \n) characters surrounding a command name within a Device Control Request Status String (DECRQSS) escape sequence in a text file, a related issue to CVE-2003-0063 and CVE-2003-0071.

Affected configurations

NVD
Node
invisible-islandxtermMatch_nil_

References

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8 High

AI Score

Confidence

High

0.012 Low

EPSS

Percentile

85.2%