USN-703-1: xterm vulnerabilities
USN-703-1: xterm vulnerabilities
Referenced CVEs:
CVE-2006-7236, CVE-2008-2383
Description:
===========================================================
Ubuntu Security Notice USN-703-1 January 06, 2009
xterm vulnerabilities
CVE-2006-7236, CVE-2008-2383
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 7.10
Ubuntu 8.04 LTS
Ubuntu 8.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
xterm 208-3.1ubuntu3.1
Ubuntu 7.10:
xterm 229-1ubuntu0.1
Ubuntu 8.04 LTS:
xterm 229-1ubuntu1.1
Ubuntu 8.10:
xterm 235-1ubuntu1.1
After a standard system upgrade you need to restart any running xterms to
effect the necessary changes.
Details follow:
Paul Szabo discovered that the DECRQSS escape sequences were not handled
correctly by xterm. Additionally, window title operations were also not
safely handled. If a user were tricked into viewing a specially crafted
series of characters while in xterm, a remote attacker could execute
arbitrary commands with user privileges. (CVE-2006-7236, CVE-2008-2382)
