Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execute arbitrary commands on the device via unspecified vectors.
References
Link Resource
https://access.redhat.com/errata/RHSA-2018:2225 Third Party Advisory
https://github.com/fluent/fluentd/blob/v0.12/CHANGELOG.md#bug-fixes Issue Tracking Release Notes Third Party Advisory
https://github.com/fluent/fluentd/pull/1733 Issue Tracking Patch Third Party Advisory
https://jvn.jp/en/vu/JVNVU95124098/index.html Issue Tracking Third Party Advisory VDB Entry
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: jpcert

Published: 2017-12-08T15:00:00

Updated: 2018-07-20T09:57:01

Reserved: 2017-07-04T00:00:00


Link: CVE-2017-10906

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2017-12-08T15:29:00.260

Modified: 2021-08-04T17:14:46.777


Link: CVE-2017-10906

JSON object: View

cve-icon Redhat Information

No data.