CVE-2007-3770

Publication date 15 July 2007

Last updated 24 July 2024


Ubuntu priority

The terminal_helper_execute function in terminal/terminal.c in Xfce Terminal 0.2.6 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a crafted link, as demonstrated using the "Open Link" functionality.

Status

Package Ubuntu Release Status
xfce4-terminal 7.04 feisty
Fixed 0.2.6-0ubuntu3.1
6.10 edgy
Fixed 0.2.5.4-0ubuntu2.1
6.06 LTS dapper
Fixed 0.2.5+r21674-0ubuntu2.1

References

Related Ubuntu Security Notices (USN)

    • USN-497-1
    • xfce4-terminal vulnerability
    • 14 August 2007

Other references