Описание
The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| rxvt-unicode | fixed | 9.31-1 | package | |
| rxvt-unicode | ignored | bookworm | package | |
| rxvt-unicode | not-affected | bullseye | package | |
| rxvt-unicode | not-affected | buster | package |
Примечания
https://www.openwall.com/lists/oss-security/2022/12/05/1
http://cvs.schmorp.de/rxvt-unicode/src/perl/background?r1=1.105&r2=1.109
Not exploitable due to a bug since 9.30 upstream
EPSS
Связанные уязвимости
The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.
The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.
The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.
EPSS