CVE-2022-4170

Name
CVE-2022-4170
Description
The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://bugzilla.redhat.com/show_bug.cgi?id=2151597
MISC https://www.openwall.com/lists/oss-security/2022/12/05/1
Third Party Advisory https://security.gentoo.org/glsa/202310-20

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:rxvt-unicode_project:rxvt-unicode:9.25:*:*:*:*:*:*:* rxvt-unicode == None == 9.25
cpe:2.3:a:rxvt-unicode_project:rxvt-unicode:9.26:*:*:*:*:*:*:* rxvt-unicode == None == 9.26

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
rxvt-unicode edge-community 9.31-r0 None fixed
rxvt-unicode edge-community 9.26-r0 Sören Tempel <soeren+alpine@soeren-tempel.net> possibly vulnerable
rxvt-unicode 3.22-community 9.31-r0 None fixed
rxvt-unicode 3.22-community 9.26-r0 None possibly vulnerable
rxvt-unicode 3.21-community 9.31-r0 None fixed
rxvt-unicode 3.20-community 9.31-r0 None fixed
rxvt-unicode 3.19-community 9.31-r0 None fixed
rxvt-unicode 3.18-community 9.31-r0 None fixed