CRLF injection vulnerability in the evalFolderLine function in fvwm 2.5.18...
Vulnerability Description
CRLF injection vulnerability in the evalFolderLine function in fvwm 2.5.18 and earlier allows local users to execute arbitrary commands via carriage returns in a directory name, which is not properly handled by fvwm-menu-directory, a variant of CVE-2003-1308.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-5969
Credits & Attribution
No credits recorded in the NVD database.
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30452
- http://www.gentoo-portage.com/x11-wm/fvwm/ChangeLog
- http://thread.gmane.org/gmane.comp.window-managers.fvwm.devel/2419/focus=2419
- http://secunia.com/advisories/22961
- http://www.gentoo.org/security/en/glsa/glsa-200611-17.xml
- http://secunia.com/advisories/23089
Affected Vendor
fvwm
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.