Lucene search

K
freebsdFreeBSD5B2EAC07-8B4D-11ED-8B23-A0F3C100AE18
HistoryDec 05, 2022 - 12:00 a.m.

rxvt-unicode is vulnerable to a remote code execution

2022-12-0500:00:00
vuxml.freebsd.org
8
rxvt-unicode
cve-2022-4170
remote code execution
urxvt
unix

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.006 Low

EPSS

Percentile

77.9%

Marc Lehmann reports:

The biggest issue is resolving CVE-2022-4170, which allows command
execution inside urxvt from within the terminal (that means anything that
can output text in the terminal can start commands in the context of the
urxvt process, even remotely).

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchrxvt-unicode< 9.31UNKNOWN

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.006 Low

EPSS

Percentile

77.9%