USN-962-1: VTE vulnerability
15 July 2010
arbitrary command execution via terminal escape codes
Releases
Packages
- vte - Terminal emulator widget for GTK+ 2.0
Details
Janne Snabb discovered that applications using VTE, such as gnome-terminal,
did not correctly filter window and icon title request escape codes. If a
user were tricked into viewing specially crafted output in their terminal,
a remote attacker could execute arbitrary commands with user privileges.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 9.10
Ubuntu 9.04
Ubuntu 10.04
After a standard system update you need to restart your session to make
all the necessary changes.