USN-6833-1: VTE vulnerability
13 June 2024
VTE could be made to consume resources and crash if it displayed specially crafted data.
Releases
Packages
- vte2.91 - Terminal emulator widget for GTK
Details
Siddharth Dushantha discovered that VTE incorrectly handled large window
resize escape sequences. An attacker could possibly use this issue to
consume resources, leading to a denial of service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.04
Ubuntu 23.10
Ubuntu 22.04
Ubuntu 20.04
In general, a standard system update will make all the necessary changes.