Executive Summary
Summary | |
---|---|
Title | Updated Hangul Terminal packages provide security fixes |
Informations | |||
---|---|---|---|
Name | RHSA-2003:071 | First vendor Publication | 2003-07-08 |
Vendor | RedHat | Last vendor Modification | 2003-07-08 |
Severity (Vendor) | N/A | Revision | 01 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Problem Description: |
Original Source
Url : https://rhn.redhat.com/errata/RHSA-2003-071.html |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 |
OpenVAS Exploits
Date | Description |
---|---|
2009-05-05 | Name : HP-UX Update for Apache HPSBUX01019 File : nvt/gb_hp_ux_HPSBUX01019.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
4918 | Hangul Terminal hanterm-xf DoS Hanterm-xf contains a flaw that may allow a remote denial of service. The issue is triggered when malformed escape sequences are injected into a user's terminal emulator session by an attacker and cause the terminal emulator to enter into a loop and crash, resulting in loss of availability for the platform. |
4917 | Hangul Terminal hanterm-xf Window Title Escape Sequence Arbitrary Command Exe... Hanterm-xf contains a flaw that may allow a malicious user to execute arbitrary commands. The issue is triggered when a user inadvertantly opens up a text file containing commands and malformed escape charaters, as a result this could modify the Windows title and result in the commands being added in the command line of the terminal windows where they could be executed if the user presses Enter. It is possible that the flaw may allow execution of arbitrary code resulting in a loss of confidentiality and integrity. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2004-09-29 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-380.nasl - Type : ACT_GATHER_INFO |
2004-07-06 | Name : The remote Red Hat host is missing a security update. File : redhat-RHSA-2003-071.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:48:04 |
|