CVE-2022-4170
Summary
| CVE | CVE-2022-4170 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-09 18:15:00 UTC |
| Updated | 2023-11-14 19:22:00 UTC |
| Description | The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Fedoraproject | Extra Packages For Enterprise Linux | 8.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 37 | All | All | All |
| Application | Rxvt-unicode Project | Rxvt-unicode | 9.25 | All | All | All |
| Application | Rxvt-unicode Project | Rxvt-unicode | 9.26 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 2151597 – (CVE-2022-4170) CVE-2022-4170 rxvt-unicode: remote code execution via background OSC | MISC | bugzilla.redhat.com | |
| oss-security - CVE-2022-4170: rxvt-unicode code execution via background OSC | MISC | www.openwall.com | |
| rxvt-unicode: Arbitrary Code Execution (GLSA 202310-20) — Gentoo security | GENTOO | security.gentoo.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 503266 Alpine Linux Security Update for rxvt-unicode
- 506238 Alpine Linux Security Update for rxvt-unicode
- 691018 Free Berkeley Software Distribution (FreeBSD) Security Update for rxvt (5b2eac07-8b4d-11ed-8b23-a0f3c100ae18)
- 710778 Gentoo Linux rxvt-unicode Arbitrary Code Execution Vulnerability (GLSA 202310-20)