<title>xterm: User-assisted arbitrary commands execution</title>
An error in the processing of special sequences in xterm may lead to
arbitrary commands execution.
<announced>February 12, 2009</announced>
<revised>February 12, 2009: 01</revised>
xterm is a terminal emulator for the X Window system.
Paul Szabo reported an insufficient input sanitization when processing
Device Control Request Status String (DECRQSS) sequences.
A remote attacker could entice a user to display a file containing
specially crafted DECRQSS sequences, possibly resulting in the remote
execution of arbitrary commands with the privileges of the user viewing
the file.
There is no known workaround at this time.
All xterm users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose &quot;&gt;=x11-terms/xterm-239&quot;</code>
<uri link="">CVE-2008-2383</uri>
