CVE-2006-7236

Severity CVSS v4.0:
Pending analysis
Type:
CWE-16 Configuration Errors
Publication date:
02/01/2009
Last modified:
09/04/2025

Description

The default configuration of xterm on Debian GNU/Linux sid and possibly Ubuntu enables the allowWindowOps resource, which allows user-assisted attackers to execute arbitrary code or have unspecified other impact via escape sequences.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:invisible-island:xterm:_nil_:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:*:*:*:*:*:*:*:*
cpe:2.3:o:ubuntu:linux:*:*:*:*:*:*:*:*