CVE-2024-37535

Publication date 9 June 2024

Last updated 24 July 2024


Ubuntu priority

GNOME VTE before 0.76.3 allows an attacker to cause a denial of service (memory consumption) via a window resize escape sequence, a related issue to CVE-2000-0476.

Read the notes from the security team

Status

Package Ubuntu Release Status
vte2.91 24.10 oracular
Not affected
24.04 LTS noble
Fixed 0.76.0-1ubuntu0.1
23.10 mantic
Fixed 0.74.0-2ubuntu0.1
22.04 LTS jammy
Fixed 0.68.0-1ubuntu0.1
20.04 LTS focal
Fixed 0.60.3-0ubuntu1~20.5
18.04 LTS bionic
Needs evaluation
16.04 LTS xenial
Needs evaluation

Notes


alexmurray

PoC in oss-security reply

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
vte2.91