7-Year-Old Critical RCE Flaw Found in Popular iTerm2 macOS Terminal App


A 7-year-old critical remote code execution vulnerability has been discovered in iTerm2 macOS terminal emulator app—one of the most popular open source replacements for Mac’s built-in terminal app.

Tracked as CVE-2019-9535, the vulnerability in iTerm2 was discovered as part of an independent security audit funded by the Mozilla Open Source Support Program (MOSS) and conducted by cybersecurity firm Radically Open Security (ROS).

“MOSS selected iTerm2 for a security audit because it processes untrusted data, and it is widely used, including by high-risk targets (like developers and system administrators),” Mozilla says.

According to a blog post published today by Mozilla, the RCE flaw resides in the tmux integration feature of iTerm2, which, if exploited, could allow an attacker to execute arbitrary commands by providing malicious output to the terminal.

As shown in the video demonstration, potential attack vectors for this vulnerability include connecting to an attacker-controlled malicious SSH server, using commands like curl to fetch a malicious website, or using tail -f to follow a log file containing some malicious content.

Web Application Firewall

Besides this, the flaw can also be triggered using command-line utilities by tricking them into printing attacker-controlled content, eventually allowing attackers to execute arbitrary commands on the user’s Mac computer.

“Typically, this vulnerability would require some degree of user interaction or trickery; but because it can be exploited via commands generally considered safe, there is a high degree of concern about the potential impact,” Mozilla warns.

The vulnerability affects iTerm2 versions up to and including 3.3.5 and has recently been patched with the release of iTerm2 3.3.6, which users can download manually or check for updates within your installed apps menu.

Products You May Like

Articles You May Like

Utah Tech CEO Jailed for Possessing Thousands of Files Depicting Child Sexual Abuse
New Android Flaw Affecting Over 1 Billion Phones Let Attackers Hijack Apps
Amid unprecedented growth on its platform, Acorns cuts roles and shuts down an office
Ola Electric acquires Etergo, to launch own line of electric two wheelers this year
Canada court finds against Huawei CFO Meng Wanzhou on double criminality; extradition trial to continue

Leave a Reply

Your email address will not be published. Required fields are marked *