CVE-2015-8971

high
Published 2017-01-23 · Modified 2026-05-13
CVSS v3
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2
4.6
VIR risk
7.8

Description

Terminology 0.7.0 allows remote attackers to execute arbitrary commands via escape sequences that modify the window title and then are written to the terminal, a similar issue to CVE-2003-0063.

Predictions

Exploit likelihood
75%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-8971

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://git.enlightenment.org/apps/terminology.git/commit/?id=b80bedc7c21ecffe99d8d142930db696eebdd6a5

OS impact

OSVersionStatusFixed in
debian debian8.0affected
debian debianbookwormfixed0.7.0-2
debian debianbullseyefixed0.7.0-2
debian debianforkyfixed0.7.0-2
debian debiansidfixed0.7.0-2
debian debiantrixiefixed0.7.0-2

Application impact

VendorProductVersionsFixed
enlightenmentterminology0.7.0

References

CWEs

CWE-77

Verify integrity in audit chain (admin only). AS-IS.