security flaw
Published Sep 1, 2004
7.3
HIGHCVSS 3.1
EPSS 3.43%
Description
The xterm terminal emulator in XFree86 4.2.0 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.
Affected products
No data.
- 4.0
- 4.0.1
- 4.0.3
- 4.1.0
- 4.2.0
- 4.2.1
-
- Version 0StatusaffectedConstraints<=4.2.0
- Version
Red Hat Enterprise Linux AS (Advanced Server) version 2.1
n/a
Fixed · RHSA-2003:065
Red Hat Enterprise Linux ES version 2.1
n/a
Fixed · RHSA-2003:065
Red Hat Enterprise Linux WS version 2.1
n/a
Fixed · RHSA-2003:065
Red Hat Linux 7.1
n/a
Fixed · RHSA-2003:064
Red Hat Linux 7.2
n/a
Fixed · RHSA-2003:064
Red Hat Linux 7.3
n/a
Fixed · RHSA-2003:066
Red Hat Linux 8.0
n/a
Fixed · RHSA-2003:067
Red Hat Linux Advanced Workstation 2.1
n/a
Fixed · RHSA-2003:065
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux AS (Advanced Server) version 2.1 | n/a | Fixed | RHSA-2003:065 |
| Red Hat Enterprise Linux ES version 2.1 | n/a | Fixed | RHSA-2003:065 |
| Red Hat Enterprise Linux WS version 2.1 | n/a | Fixed | RHSA-2003:065 |
| Red Hat Linux 7.1 | n/a | Fixed | RHSA-2003:064 |
| Red Hat Linux 7.2 | n/a | Fixed | RHSA-2003:064 |
| Red Hat Linux 7.3 | n/a | Fixed | RHSA-2003:066 |
| Red Hat Linux 8.0 | n/a | Fixed | RHSA-2003:067 |
| Red Hat Linux Advanced Workstation 2.1 | n/a | Fixed | RHSA-2003:065 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Jul 24, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.43% (0.03431) | 88.55th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.40% (0.03403) | 87.26th | v5 (v2026.06.15) |
| Mar 30, 2025 | 1.13% (0.01131) | 76.37th | v4 (v2025.03.14) |
| Mar 29, 2025 | 2.23% (0.02226) | 74.13th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.98% (0.00976) | 75.13th | v4 (v2025.03.14) |
| Dec 12, 2024 | 1.08% (0.01077) | 84.92th | v3 (v2023.03.01) |
| Jul 9, 2024 | 1.08% (0.01077) | 84.37th | v3 (v2023.03.01) |
| Aug 9, 2023 | 1.07% (0.01072) | 82.37th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.36% (0.01363) | 84.12th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.54% (0.01537) | 74.52th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.54% (0.01537) | 74.48th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.54% (0.01537) | 72.41th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.54% (0.01537) | 51.33th | v2 (v2022.01.01) |
No CWE recorded.
References (14)
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html mailing-listVendor Advisory
- http://marc.info/?l=bugtraq&m=104612710031920&w=2 mailing-list
- http://www.debian.org/security/2003/dsa-380 vendor-advisory
- http://www.iss.net/security_center/static/11414.php vdb-entryVendor Advisory
- http://www.openwall.com/lists/oss-security/2024/06/15/1 mailing-list
- http://www.redhat.com/support/errata/RHSA-2003-064.html vendor-advisory
- http://www.redhat.com/support/errata/RHSA-2003-065.html vendor-advisory
- http://www.redhat.com/support/errata/RHSA-2003-066.html vendor-advisory
- http://www.redhat.com/support/errata/RHSA-2003-067.html vendor-advisory
- http://www.securityfocus.com/bid/6940 vdb-entry
- https://access.redhat.com/security/cve/CVE-2003-0063 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1616948 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2003-0063
- https://www.cve.org/CVERecord?id=CVE-2003-0063
| Link | Providers | Tags |
|---|---|---|
| http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html | mailing-listVendor Advisory | |
| http://marc.info/?l=bugtraq&m=104612710031920&w=2 | mailing-list | |
| http://www.debian.org/security/2003/dsa-380 | vendor-advisory | |
| http://www.iss.net/security_center/static/11414.php | vdb-entryVendor Advisory | |
| http://www.openwall.com/lists/oss-security/2024/06/15/1 | mailing-list | |
| http://www.redhat.com/support/errata/RHSA-2003-064.html | vendor-advisory | |
| http://www.redhat.com/support/errata/RHSA-2003-065.html | vendor-advisory | |
| http://www.redhat.com/support/errata/RHSA-2003-066.html | vendor-advisory | |
| http://www.redhat.com/support/errata/RHSA-2003-067.html | vendor-advisory | |
| http://www.securityfocus.com/bid/6940 | vdb-entry | |
| https://access.redhat.com/security/cve/CVE-2003-0063 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1616948 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2003-0063 | ||
| https://www.cve.org/CVERecord?id=CVE-2003-0063 |
Change history (0)
No recorded changes yet.