Description

An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in combination with the built-in tmux integration feature (enabled by default), allows an attacker to inject arbitrary code into the terminal, a different vulnerability than CVE-2024-38395.

INFO

Published Date :

2024-06-16T00:00:00.000Z

Last Modified :

2024-08-02T04:12:24.434Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2024-38396 vulnerability.

Vendors Products
Gnachman
  • Iterm2
Iterm2
  • Iterm2

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact