CVE-2022-24130
Summary
| CVE | CVE-2022-24130 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-31 05:15:00 UTC |
| Updated | 2023-11-07 03:44:00 UTC |
| Description | xterm through Patch 370, when Sixel support is enabled, allows attackers to trigger a buffer overflow in set_sixel in graphics_sixel.c via crafted text. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| XTERM - Change Log |
MISC |
invisible-island.net |
|
| JavaScript is not available. |
MISC |
twitter.com |
|
| xterm: Multiple Vulnerabilities (GLSA 202208-22) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] Fedora 34 Update: xterm-370-3.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 35 Update: xterm-370-3.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] [DLA 2913-1] xterm security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 35 Update: xterm-370-3.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| oss-security - xterm buffer overflow via crafted sixel |
MISC |
www.openwall.com |
|
| oss-security - Re: xterm buffer overflow via crafted sixel |
MISC |
www.openwall.com |
|
| [SECURITY] Fedora 34 Update: xterm-370-3.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179058 Debian Security Update for xterm (DLA 2913-1)
- 179198 Debian Security Update for xterm (CVE-2022-24130)
- 282393 Fedora Security Update for xterm (FEDORA-2022-965978ed67)
- 282394 Fedora Security Update for xterm (FEDORA-2022-9bf751cdf7)
- 296063 Oracle Solaris 11.4 Support Repository Update (SRU) 45.119.2 Missing (CPUAPR2022)
- 502204 Alpine Linux Security Update for xterm
- 671597 EulerOS Security Update for xterm (EulerOS-SA-2022-1593)
- 710689 Gentoo Linux xterm Multiple Vulnerabilities (GLSA 202208-22)
- 752790 SUSE Enterprise Linux Security Update for xterm (SUSE-SU-2022:3953-1)
- 752791 SUSE Enterprise Linux Security Update for xterm (SUSE-SU-2022:3952-1)
- 900915 Common Base Linux Mariner (CBL-Mariner) Security Update for xterm (8456)
- 903873 Common Base Linux Mariner (CBL-Mariner) Security Update for xterm (8456-1)