CVE-2006-5969

Publication date 17 November 2006

Last updated 17 July 2025


Ubuntu priority

Description

CRLF injection vulnerability in the evalFolderLine function in fvwm 2.5.18 and earlier allows local users to execute arbitrary commands via carriage returns in a directory name, which is not properly handled by fvwm-menu-directory, a variant of CVE-2003-1308.

Status

Package Ubuntu Release Status
fvwm 9.10 karmic
Fixed 2.5.21-1
9.04 jaunty
Fixed 2.5.21-1
8.10 intrepid
Fixed 2.5.21-1
8.04 LTS hardy
Fixed 2.5.21-1
7.10 gutsy
Fixed 2.5.21-1
7.04 feisty Ignored end of life, was needed
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life