This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple Terminal. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The specific flaw exists in the handling of ‘CSI[4’ xterm window resizing escape code. When a very low negative value for (x, y) size is set, an integer overflow occurs resulting in a memory corruption. This can be further leveraged to execute arbitrary code under the context of the logged in user.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/78027/TPTI-09-04.txt
Source: https://packetstormsecurity.com/files/78027/Apple-Terminal-xterm-Resize-Escape-Sequence-Memory-Corruption.html

