DescriptionThe "screen dump" feature in Eterm 0.9.1 and earlier allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to a user's terminal, e.g. when the user views a file containing the malicious sequence.
eterm (PTS)stretch0.9.6-5fixed
stretch (security)0.9.6-5+deb9u1fixed
bullseye, sid0.9.6-6.1fixed

According to upstream changelog
this is fixed in eterm 0.9.2

