Debian Rxvt-Unicode vulnerabilities

6 known vulnerabilities affecting debian/rxvt-unicode.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2022-4170CRITICALCVSS 9.8fixed in rxvt-unicode 9.31-1 (forky)2022
CVE-2022-4170 [CRITICAL] CVE-2022-4170: rxvt-unicode - The rxvt-unicode package is vulnerable to a remote code execution, in the Perl b... The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set. Scope: local bookworm: open bullseye: resolved forky: resolved (fixed in 9.31-1) sid: resolved (fixed in 9.31-1) trixie: resolved (fixed in 9.31-1)
debian
CVE-2021-33477HIGHCVSS 8.8fixed in eterm 0.9.6-6.1 (bookworm)2021
CVE-2021-33477 [HIGH] CVE-2021-33477: eterm - rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially ... rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q). A response is terminated by a newline. Scope: local bookworm: resolved (fixed in 0.9.6-6.1) bullseye: resolved (fixed in 0.9.6-6.1) forky: resolved (fixed in 0.9.6-6.1) sid: resolved (fixed in 0.9.6-
debian
CVE-2014-3121HIGHCVSS 7.6fixed in rxvt-unicode 9.20-1 (bookworm)2014
CVE-2014-3121 [HIGH] CVE-2014-3121: rxvt-unicode - rxvt-unicode before 9.20 does not properly handle OSC escape sequences, which al... rxvt-unicode before 9.20 does not properly handle OSC escape sequences, which allows user-assisted remote attackers to manipulate arbitrary X window properties and execute arbitrary commands. Scope: local bookworm: resolved (fixed in 9.20-1) bullseye: resolved (fixed in 9.20-1) forky: resolved (fixed in 9.20-1) sid: resolved (fixed in 9.20-1) trixie: resolved (fi
debian
CVE-2006-0126MEDIUMCVSS 4.6fixed in rxvt-unicode 6.3-1 (bookworm)2006
CVE-2006-0126 [MEDIUM] CVE-2006-0126: rxvt-unicode - rxvt-unicode before 6.3, on certain platforms that use openpty and non-Unix pty ... rxvt-unicode before 6.3, on certain platforms that use openpty and non-Unix pty devices such as Linux and most BSD platforms, does not maintain the intended permissions of tty devices, which allows local users to gain read and write access to the devices. Scope: local bookworm: resolved (fixed in 6.3-1) bullseye: resolved (fixed in 6.3-1) forky: resolved (fixed
debian
CVE-2005-0764HIGHCVSS 7.5fixed in rxvt-unicode 5.3-1 (bookworm)2005
CVE-2005-0764 [HIGH] CVE-2005-0764: rxvt-unicode - Buffer overflow in command.C for rxvt-unicode before 5.3 allows remote attackers... Buffer overflow in command.C for rxvt-unicode before 5.3 allows remote attackers to execute arbitrary code via a crafted file containing long escape sequences. Scope: local bookworm: resolved (fixed in 5.3-1) bullseye: resolved (fixed in 5.3-1) forky: resolved (fixed in 5.3-1) sid: resolved (fixed in 5.3-1) trixie: resolved (fixed in 5.3-1)
debian
CVE-2004-2215MEDIUMCVSS 4.6fixed in rxvt-unicode 3.8-1 (bookworm)2004
CVE-2004-2215 [MEDIUM] CVE-2004-2215: rxvt-unicode - RXVT-Unicode 3.4 and 3.5 does not properly close file descriptors, which allows ... RXVT-Unicode 3.4 and 3.5 does not properly close file descriptors, which allows local users to access the terminals of other users and possibly gain privileges. Scope: local bookworm: resolved (fixed in 3.8-1) bullseye: resolved (fixed in 3.8-1) forky: resolved (fixed in 3.8-1) sid: resolved (fixed in 3.8-1) trixie: resolved (fixed in 3.8-1)
debian