Server side template injection In xfce4-terminal
Description
The terminal_helper_execute function in terminal/terminal.c in Xfce Terminal 0.2.6 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a crafted link, as demonstrated using the "Open Link" functionality.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 14 | 0.2.6-3 | ||
debian 12 | 0.2.6-3 | ||
debian 13 | 0.2.6-3 |
Aliases
1. 2. 3. 4. 5.