Terminal character injection in Mintty before 3.6.3 allows code execution via unescaped output to the terminal.
References
Link | Resource |
---|---|
https://dgl.cx/2023/09/ansi-terminal-security#mintty | Exploit |
https://github.com/mintty/mintty/releases/tag/3.6.3 | Release Notes |
Configurations
History
No history.
Information
Published : 2023-10-19 16:15
Updated : 2023-10-25 19:46
NVD link : CVE-2022-47583
Mitre link : CVE-2022-47583
CVE.ORG link : CVE-2022-47583
JSON object : View
Products Affected
mintty_project
- mintty
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')