Vulnerability Name:
CVE-2003-0023 (CCN-11416)
Assigned:
2003-02-24
Published:
2003-02-24
Updated:
2016-10-18
Summary:
The menuBar feature in rxvt 2.7.8 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu.
CVSS v3 Severity:
5.3 Medium
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
Low
Availibility (A):
None
CVSS v2 Severity:
5.0 Medium
(CVSS v2 Vector:
AV:N/AC:L/Au:N/C:N/I:P/A:N
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
Partial
Availibility (A):
None
5.0 Medium
(CCN CVSS v2 Vector:
AV:N/AC:L/Au:N/C:N/I:P/A:N
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
Partial
Availibility (A):
None
Vulnerability Type:
CWE-Other
Vulnerability Consequences:
Gain Access
References:
Source: CCN
Type: BugTraq Mailing List, Mon Feb 24 2003 - 20:09:39 CST
Re: Terminal Emulator Security Issues
Source: CCN
Type: VulnWatch Mailing List, Mon Feb 24 2003 - 15:02:52 CST
Terminal Emulator Security Issues
Source: VULNWATCH
Type: Vendor Advisory
20030224 Terminal Emulator Security Issues
Source: CCN
Type: aterm Web site
Aterm - AfterStep X Windows Terminal Emulator
Source: MITRE
Type: CNA
CVE-2003-0023
Source: MITRE
Type: CNA
CVE-2003-0024
Source: BUGTRAQ
Type: UNKNOWN
20030224 Terminal Emulator Security Issues
Source: CCN
Type: RHSA-2003-054
Updated rxvt packages fix various vulnerabilites
Source: CCN
Type: RHSA-2003-055
rxvt security update
Source: XF
Type: Vendor Advisory
terminal-emulator-menu-modification(11416)
Source: MANDRAKE
Type: UNKNOWN
MDKSA-2003:034
Source: REDHAT
Type: UNKNOWN
RHSA-2003:054
Source: REDHAT
Type: UNKNOWN
RHSA-2003:055
Source: BID
Type: UNKNOWN
6947
Source: CCN
Type: BID-6947
RXVT Menu Bar Escape Sequence Command Execution Vulnerability
Source: CCN
Type: BID-6949
ATerm Menu Bar Escape Sequence Command Execution Vulnerability
Source: CCN
Type: BID-9930
Apache Error and Access Logs Escape Sequence Injection Vulnerability
Source: CCN
Type: TLSA-2003-19
A number of vulnerabilities in the handling of escape sequences
Source: XF
Type: UNKNOWN
terminal-emulator-menu-modification(11416)
Vulnerable Configuration:
Configuration 1
:
cpe:/a:rxvt:rxvt:2.6.1:*:*:*:*:*:*:*
OR
cpe:/a:rxvt:rxvt:2.6.2:*:*:*:*:*:*:*
OR
cpe:/a:rxvt:rxvt:2.6.3:*:*:*:*:*:*:*
OR
cpe:/a:rxvt:rxvt:2.6.4:*:*:*:*:*:*:*
OR
cpe:/a:rxvt:rxvt:2.7.5:*:*:*:*:*:*:*
OR
cpe:/a:rxvt:rxvt:2.7.6:*:*:*:*:*:*:*
OR
cpe:/a:rxvt:rxvt:2.7.7:*:*:*:*:*:*:*
OR
cpe:/a:rxvt:rxvt:2.7.8:*:*:*:*:*:*:*
Configuration CCN 1
:
cpe:/a:rxvt:rxvt:2.7.8:*:*:*:*:*:*:*
AND
cpe:/o:redhat:linux:6.2:*:*:*:*:*:*:*
OR
cpe:/o:redhat:linux:7:*:*:*:*:*:*:*
OR
cpe:/o:redhat:linux:7.1:*:*:*:*:*:*:*
OR
cpe:/o:redhat:linux:7.2:*:*:*:*:*:*:*
OR
cpe:/o:mandrakesoft:mandrake_linux:8.2:*:*:*:*:*:*:*
OR
cpe:/o:redhat:linux:7.3:*:*:*:*:*:*:*
OR
cpe:/o:mandrakesoft:mandrake_linux:9.0:*:*:*:*:*:*:*
OR
cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1:*:*:*:*:*:*:*
OR
cpe:/o:mandrakesoft:mandrake_linux:9.1:*:*:*:*:*:*:*
OR
cpe:/o:redhat:enterprise_linux:2.1:*:as:*:*:*:*:*
OR
cpe:/o:redhat:enterprise_linux:2.1:*:es:*:*:*:*:*
OR
cpe:/o:redhat:enterprise_linux:2.1:*:ws:*:*:*:*:*
OR
cpe:/o:redhat:linux_advanced_workstation:2.1::itanium:*:*:*:*:*
OR
cpe:/o:mandrakesoft:mandrake_linux:8.2::ppc:*:*:*:*:*
OR
cpe:/o:mandrakesoft:mandrake_linux:9.1::ppc:*:*:*:*:*
Denotes that component is vulnerable
BACK
rxvt
rxvt 2.6.1
rxvt
rxvt 2.6.2
rxvt
rxvt 2.6.3
rxvt
rxvt 2.6.4
rxvt
rxvt 2.7.5
rxvt
rxvt 2.7.6
rxvt
rxvt 2.7.7
rxvt
rxvt 2.7.8
rxvt
rxvt 2.7.8
redhat
linux 6.2
redhat
linux 7
redhat
linux 7.1
redhat
linux 7.2
mandrakesoft
mandrake linux 8.2
redhat
linux 7.3
mandrakesoft
mandrake linux 9.0
mandrakesoft
mandrake linux corporate server 2.1
mandrakesoft
mandrake linux 9.1
redhat
enterprise linux 2.1
redhat
enterprise linux 2.1
redhat
enterprise linux 2.1
redhat
linux advanced workstation 2.1
mandrakesoft
mandrake linux 8.2
mandrakesoft
mandrake linux 9.1