CVE-2019-0542
published 2019-01-09CVE-2019-0542: A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerability."…
PriorityP349high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
3.18%
86.7th percentile
A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerability." This affects xterm.js.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-xterm | < node-xterm 3.8.1-1 (bookworm) | node-xterm 3.8.1-1 (bookworm) |
| https | xtermjs.org_xterm.js | — | — |
| invisible-island | xterm | >= 0 < 3.8.1 | 3.8.1 |
| invisible-island | xterm | >= 3.10.0 < 3.10.1 | 3.10.1 |
| invisible-island | xterm | >= 3.9.0 < 3.9.2 | 3.9.2 |
| redhat | openshift_container_platform | < 3.11.104 | 3.11.104 |
| redhat | openshift_container_platform | >= 3.10 < 3.10.163 | 3.10.163 |
| redhat | openshift_container_platform | >= 3.9 < 3.9.99 | 3.9.99 |
| xtermjs | xterm.js | < 5.0.0 | 5.0.0 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8LOW
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xterm.js: Mishandling of special characters allows for remote code execution
vendor_redhat·2019-01-09·CVSS 8.8
CVE-2019-0542 [HIGH] CWE-77 xterm.js: Mishandling of special characters allows for remote code execution
xterm.js: Mishandling of special characters allows for remote code execution
A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerability." This affects xterm.js.
It was found that xterm.js does not sanitize terminal escape sequences in browser terminals allowing for execution of arbitrary commands. An attacker could exploit this by convincing a user with a xterm.js browser terminal to display an escape sequence by, for example, reading a from a log file containing attacker-controlled input.
Statement: This issue affects both the atomic-openshift-web-console RPM and openshift3/ose-console container image shipped in OpenShift Container Platform. These components provide a web console for opening
Debian
CVE-2019-0542: node-xterm - A remote code execution vulnerability exists in Xterm.js when the component mish...
vendor_debian·2019·CVSS 8.8
CVE-2019-0542 [HIGH] CVE-2019-0542: node-xterm - A remote code execution vulnerability exists in Xterm.js when the component mish...
A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerability." This affects xterm.js.
Scope: local
bookworm: resolved (fixed in 3.8.1-1)
bullseye: resolved (fixed in 3.8.1-1)
forky: resolved (fixed in 3.8.1-1)
sid: resolved (fixed in 3.8.1-1)
trixie: resolved (fixed in 3.8.1-1)
OSV
xterm vulnerable to remote code execution
osv·2019-01-14
CVE-2019-0542 [HIGH] xterm vulnerable to remote code execution
xterm vulnerable to remote code execution
A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters.
GHSA
xterm vulnerable to remote code execution
ghsa·2019-01-14
CVE-2019-0542 [HIGH] CWE-94 xterm vulnerable to remote code execution
xterm vulnerable to remote code execution
A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters.
OSV
CVE-2019-0542: A remote code execution vulnerability exists in Xterm
osv·2019-01-09·CVSS 8.8
CVE-2019-0542 [HIGH] CVE-2019-0542: A remote code execution vulnerability exists in Xterm
A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerability." This affects xterm.js.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/106434https://access.redhat.com/errata/RHBA-2019:0959https://access.redhat.com/errata/RHSA-2019:1422https://access.redhat.com/errata/RHSA-2019:2551https://access.redhat.com/errata/RHSA-2019:2552https://github.com/xtermjs/xterm.js/releaseshttp://www.securityfocus.com/bid/106434https://access.redhat.com/errata/RHBA-2019:0959https://access.redhat.com/errata/RHSA-2019:1422https://access.redhat.com/errata/RHSA-2019:2551https://access.redhat.com/errata/RHSA-2019:2552https://github.com/xtermjs/xterm.js/releases
2019-01-09
Published