Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3cch-wj7f-8g8x

Опубликовано: 10 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions.

xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions.

EPSS

Процентиль: 90%
0.05547
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 2 лет назад

xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions.

CVSS3: 7.4
redhat
больше 2 лет назад

xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions.

CVSS3: 9.8
nvd
больше 2 лет назад

xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions.

CVSS3: 9.8
debian
больше 2 лет назад

xterm before 375 allows code execution via font ops, e.g., because an ...

suse-cvrf
больше 2 лет назад

Security update for xterm

EPSS

Процентиль: 90%
0.05547
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-77