PublicDate: 2007-07-15 21:30:00 UTC Candidate: CVE-2007-3770 References: https://ubuntu.com/security/notices/USN-497-1 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3770 Description: The terminal_helper_execute function in terminal/terminal.c in Xfce Terminal 0.2.6 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a crafted link, as demonstrated using the "Open Link" functionality. Ubuntu-Description: Notes: Priority: untriaged Discovered-by: Assigned-to: CVSS: Bugs: dapper_xfce4-terminal: released (0.2.5+r21674-0ubuntu2.1) edgy_xfce4-terminal: released (0.2.5.4-0ubuntu2.1) feisty_xfce4-terminal: released (0.2.6-0ubuntu3.1) devel_xfce4-terminal: released (0.2.6-3ubuntu1) upstream_xfce4-terminal: needs-triage