The vte_sequence_handler_window_manipulation function in vteseq.c in libvte (aka libvte9) in VTE 0.25.1 and earlier, as used in gnome-terminal, does not properly handle escape sequences, which allows remote attackers to execute arbitrary commands or obtain potentially sensitive information via a (1) window title or (2) icon title sequence. NOTE: this issue exists because of a CVE-2003-0070 regression.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade vte | Jul 30, 2024 | Aug 5, 2010 |
| Freebsd | — | Upgrade vte | Dec 10, 2025 | Jul 18, 2010 |
| Gentoo Linux | — | Upgrade sys-cluster/ganglia.Upgrade x11-misc/slock.Upgrade x11-libs/vte.Upgrade net-analyzer/lft.Upgrade www-apps/egroupware.Upgrade net-im/gg-transport.Upgrade dev-php/suhosin. | Oct 30, 2017 | Aug 5, 2010 |
| Suse | — | Upgrade vte-develUpgrade vte-docUpgrade vte-langUpgrade vte | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libvte9 | Nov 8, 2024 | Aug 5, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub