CVE-2024-38396
June 16, 2024, 9:15 p.m.
Tags
Product(s) Impacted
iTerm2
- 3.5.x before 3.5.2
Description
An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in combination with the built-in tmux integration feature (enabled by default), allows an attacker to inject arbitrary code into the terminal, a different vulnerability than CVE-2024-38395.
Weaknesses
Date
Published: June 16, 2024, 9:15 p.m.
Last Modified: June 16, 2024, 9:15 p.m.
Status : Received
CVE has been recently published to the CVE List and has been received by the NVD.
More infoSource
cve@mitre.org
References
https://gitlab.com/
cve@mitre.org
https://iterm2.com/
cve@mitre.org
https://vin01.github.io/
cve@mitre.org