NA

CVE-2022-4170

Published: 09/12/2022 Updated: 14/11/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rxvt-unicode project rxvt-unicode 9.25

rxvt-unicode project rxvt-unicode 9.26

fedoraproject extra packages for enterprise linux 8.0

fedoraproject fedora 37

Vendor Advisories

Debian Bug report logs - #1025489 rxvt-unicode: CVE-2022-4170 Package: src:rxvt-unicode; Maintainer for src:rxvt-unicode is Ryan Kavanagh <rak@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 5 Dec 2022 18:30:01 UTC Severity: important Tags: security, upstream Found in version rxvt-unic ...