Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2008-2383

Published: 2 January 2009

CRLF injection vulnerability in xterm allows user-assisted attackers to execute arbitrary commands via LF (aka \n) characters surrounding a command name within a Device Control Request Status String (DECRQSS) escape sequence in a text file, a related issue to CVE-2003-0063 and CVE-2003-0071.

Priority

Medium

Status

Package Release Status
xterm
Launchpad, Ubuntu, Debian
dapper
Released (208-3.1ubuntu3.1)
gutsy
Released (229-1ubuntu0.1)
hardy
Released (229-1ubuntu1.1)
intrepid
Released (235-1ubuntu1.1)
upstream Needs triage