Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23491
HistoryApr 10, 2020 - 12:28 a.m.

CRLF Injection

2020-04-1000:28:46
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.012 Low

EPSS

Percentile

85.1%

Xterm is vulnerable to CRLF Injection. A flaw was found in the xterm handling of Device Control Request Status String (DECRQSS) escape sequences. An attacker could create a malicious text file (or log entry, if unfiltered) that could run arbitrary commands if read by a victim inside an xterm window.

References