Back

MEDIUM

CRLF injection vulnerability in fvwm-menu-directory for fvwm 2.5.x before 2.5.10 and 2.4.x before 2.4.18 allows local users to execute arbitrary commands via carriage returns in a filename

Published Nov 17, 2006

Description

CRLF injection vulnerability in fvwm-menu-directory for fvwm 2.5.x before 2.5.10 and 2.4.x before 2.4.18 allows local users to execute arbitrary commands via carriage returns in a filename.

Affected products

Remediation

Red Hat statement

Not vulnerable. Red Hat Enterprise Linux 2.1 shipped with fvwm, however this issue does not affect the included version of fvwm.

Metrics

Weaknesses (0)

No CWE recorded.

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 17, 2006
Updated Sep 16, 2024
Reserved Nov 17, 2006
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a