The well-known open source terminal emulator iTerm2 recently released a critical security update to fix a bug in the SSH integration function. This bug will cause the user's input and output records to be written to the remote file /tmp/framer.txt, which can also be read by other users on the remote host.
Affected include any test version of iTerm23.5.6, 3.5.7, 3.5.8, 3.5.9, 3.5.10, 3.5.6 and higher. The newly launched repair version is iTerm23.5.11. Users using iTerm2 are asked to update to the latest version immediately.
This critical error occurs when the following two conditions are true:
1. If the user uses the it2ssh command or sets the command pop-up menu in Settings, Configuration File, and General to SSH and selects SSH integration.
2. The remote host has installed Python 3.7 and higher and is installed in the default search path.
What should the user do?
First, you need to upgrade to iTerm version 23.5.11 immediately, and then delete the /tmp/framer.txt file on the remote host. After this repair, the code for SSH integration to write the log file has been deleted and similar errors will not occur again.
The latest version download address: https://iterm2.com/downloads/stable/iTerm2-3_5_11.zip