ConEmu through 220807 and Cmder before 1.3.21 report the title of the terminal, including control characters, which allows an attacker to change the title and then execute it as commands.
References
Link | Resource |
---|---|
https://gist.github.com/dgl/05ca60cdc7efc9e47bbc58d0c952635e | Third Party Advisory |
https://gist.github.com/dgl/05ca60cdc7efc9e47bbc58d0c952635e | Third Party Advisory |
https://github.com/cmderdev/cmder/blob/master/CHANGELOG.md | Release Notes |
https://github.com/cmderdev/cmder/blob/master/CHANGELOG.md | Release Notes |
Configurations
History
19 Feb 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/cmderdev/cmder/blob/master/CHANGELOG.md - Release Notes | |
References | () https://gist.github.com/dgl/05ca60cdc7efc9e47bbc58d0c952635e - Third Party Advisory | |
CPE | cpe:2.3:a:conemu_project:conemu:*:*:*:*:*:*:*:* |
cpe:2.3:a:cmder:cmder:*:*:*:*:*:*:*:* cpe:2.3:a:maximus5:conemu:*:*:*:*:*:*:*:* |
First Time |
Cmder cmder
Maximus5 conemu Cmder Maximus5 |
05 Apr 2023, 03:37
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-noinfo | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
References | (MISC) https://github.com/cmderdev/cmder/blob/master/CHANGELOG.md - Release Notes | |
References | (MISC) https://gist.github.com/dgl/05ca60cdc7efc9e47bbc58d0c952635e - Third Party Advisory | |
CPE | cpe:2.3:a:conemu_project:conemu:*:*:*:*:*:*:*:* cpe:2.3:a:cmder_project:cmder:*:*:*:*:*:*:*:* |
|
First Time |
Conemu Project conemu
Cmder Project cmder Cmder Project Conemu Project |
Information
Published : 2023-03-28 20:15
Updated : 2025-02-19 19:15
NVD link : CVE-2022-46387
Mitre link : CVE-2022-46387
JSON object : View
Products Affected
cmder
- cmder
maximus5
- conemu
CWE