Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2003-0077 | First vendor Publication | 2003-03-18 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The hanterm (hanterm-xf) terminal emulator 2.0.5 and earlier, and possibly later versions, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0077 |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
4917 | Hangul Terminal hanterm-xf Window Title Escape Sequence Arbitrary Command Exe... Hanterm-xf contains a flaw that may allow a malicious user to execute arbitrary commands. The issue is triggered when a user inadvertantly opens up a text file containing commands and malformed escape charaters, as a result this could modify the Windows title and result in the commands being added in the command line of the terminal windows where they could be executed if the user presses Enter. It is possible that the flaw may allow execution of arbitrary code resulting in a loss of confidentiality and integrity. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2004-07-06 | Name : The remote Red Hat host is missing a security update. File : redhat-RHSA-2003-071.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:23:34 |
|
2024-11-28 12:05:30 |
|
2021-05-05 01:01:25 |
|
2021-04-22 01:02:06 |
|
2020-05-23 01:35:53 |
|
2020-05-23 00:15:20 |
|
2016-10-18 12:01:08 |
|
2016-06-28 15:01:43 |
|
2016-04-26 12:30:00 |
|
2014-02-17 10:25:47 |
|
2013-05-11 11:50:27 |
|