Directory traversal vulnerability in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to read files with short names, and local users to read more files using a symlink with a short name, via a .. in the TTY argument.
| Software | From | Fixed in |
|---|---|---|
| xtell / xtell | 2.6.1 | 2.6.1.x |
| xtell / xtell | 1.91.1 | 1.91.1.x |