ConEmu before commit 230724 does not sanitize title responses correctly for control characters, potentially leading to arbitrary code execution. This is related to an incomplete fix for CVE-2022-46387.
[
{
"digest": {
"function_hash": "236050266693658837904020056679501320995",
"length": 843.0
},
"id": "CVE-2023-39150-146f0129",
"signature_version": "v1",
"target": {
"file": "src/ConEmuCD/ConAnsiImpl.cpp",
"function": "SrvAnsiImpl::ReportString"
},
"source": "https://github.com/conemu/conemu/commit/60683a186628ffaa7689fcb64b3c38ced69287c1",
"deprecated": false,
"signature_type": "Function"
},
{
"digest": {
"line_hashes": [
"276735128647626600038641527703620279184",
"189055906016559606029926632905606256321",
"225659710436854024509446302234888933330",
"60051500651401967419131112798734456981",
"216225919381866589900664575215532652285"
],
"threshold": 0.9
},
"id": "CVE-2023-39150-d0b55418",
"signature_version": "v1",
"target": {
"file": "src/ConEmuCD/ConAnsiImpl.cpp"
},
"source": "https://github.com/conemu/conemu/commit/60683a186628ffaa7689fcb64b3c38ced69287c1",
"deprecated": false,
"signature_type": "Line"
},
{
"digest": {
"line_hashes": [
"323038792857170766104563082758013077727",
"137411922499104661692274094547256715283",
"225659710436854024509446302234888933330",
"60051500651401967419131112798734456981"
],
"threshold": 0.9
},
"id": "CVE-2023-39150-d0c93692",
"signature_version": "v1",
"target": {
"file": "src/ConEmuHk/Ansi.cpp"
},
"source": "https://github.com/conemu/conemu/commit/60683a186628ffaa7689fcb64b3c38ced69287c1",
"deprecated": false,
"signature_type": "Line"
},
{
"digest": {
"function_hash": "107120160089813513627726103293137038458",
"length": 968.0
},
"id": "CVE-2023-39150-f034434a",
"signature_version": "v1",
"target": {
"file": "src/ConEmuHk/Ansi.cpp",
"function": "CEAnsi::ReportString"
},
"source": "https://github.com/conemu/conemu/commit/60683a186628ffaa7689fcb64b3c38ced69287c1",
"deprecated": false,
"signature_type": "Function"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-39150.json"