CVE-2006-5969
Publication date 17 November 2006
Last updated 17 July 2025
Ubuntu priority
Description
CRLF injection vulnerability in the evalFolderLine function in fvwm 2.5.18 and earlier allows local users to execute arbitrary commands via carriage returns in a directory name, which is not properly handled by fvwm-menu-directory, a variant of CVE-2003-1308.