Description
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From 3.0.6 to 3.8.8, This vulnerability is fixed in 3.9.0.
Problem types
CWE-94: Improper Control of Generation of Code ('Code Injection')
CWE-732: Incorrect Permission Assignment for Critical Resource
CWE-940: Improper Verification of Source of a Communication Channel
Product status
References
github.com/...ecterm/security/advisories/GHSA-7p5m-v798-f8vv
github.com/...ommit/0599e67069b00e376a2e962649aaad6096e63507