xterm: User-assisted arbitrary commands execution — GLSA 200902-04

An error in the processing of special sequences in xterm may lead to arbitrary commands execution.

Affected packages

x11-terms/xterm on all architectures
Affected versions < 239
Unaffected versions >= 239

Background

xterm is a terminal emulator for the X Window system.

Description

Paul Szabo reported an insufficient input sanitization when processing Device Control Request Status String (DECRQSS) sequences.

Impact

A remote attacker could entice a user to display a file containing specially crafted DECRQSS sequences, possibly resulting in the remote execution of arbitrary commands with the privileges of the user viewing the file.

Workaround

There is no known workaround at this time.

Resolution

All xterm users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=x11-terms/xterm-239"

References

Release date
February 12, 2009

Latest revision
February 12, 2009: 01

Severity
normal

Exploitable
remote

Bugzilla entries