CRLF injection vulnerability in xterm allows user-assisted attackers to execute arbitrary commands via LF (aka \n) characters surrounding a command name within a Device Control Request Status String (DECRQSS) escape sequence in a text file, a related issue to CVE-2003-0063 and CVE-2003-0071.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx X11 | — | Upgrade macOS to the latest version | Dec 16, 2011 | Jan 2, 2009 |
| Centos_linux | — | Upgrade xterm | Dec 1, 2016 | Jan 2, 2009 |
| Debian | — | Upgrade xterm | Jul 30, 2024 | Jan 2, 2009 |
| Freebsd | — | Upgrade xterm | Dec 10, 2025 | Jan 5, 2009 |
| Gentoo Linux | — | Upgrade x11-terms/xterm. | Oct 30, 2017 | Jan 2, 2009 |
| Oracle_linux | — | Upgrade xterm | Oct 16, 2024 | Jan 2, 2009 |
| Suse | — | Upgrade kitty-terminfoUpgrade xtermUpgrade kittyUpgrade xterm-resizeUpgrade xterm-binUpgrade kitty-shell-integration | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade xterm | Nov 8, 2024 | Jan 2, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub