Submitted by KeesCook on Tue, 2007-08-14 03:32
Referenced CVEs:
CVE-2007-3770
Description:
===========================================================
Ubuntu Security Notice USN-497-1 August 14, 2007
xfce4-terminal vulnerability
CVE-2007-3770
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
xfce4-terminal 0.2.5+r21674-0ubuntu2.1
Ubuntu 6.10:
xfce4-terminal 0.2.5.4-0ubuntu2.1
Ubuntu 7.04:
xfce4-terminal 0.2.6-0ubuntu3.1
After a standard system upgrade you need to restart your session to
effect the necessary changes.
Details follow:
Lasse Kärkkäinen discovered that the Xfce Terminal did not correctly
escape shell meta-characters during "Open Link" actions. If a remote
attacker tricked a user into opening a specially crafted URI, they could
execute arbitrary commands with the user's privileges.


