rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q). A response is terminated by a newline.
2021-05-20T20:15:07.397
2024-11-21T06:08:54.250
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | eterm_project | eterm | 0.9.7 | Yes |
Application | mrxvt_project | mrxvt | 0.5.4 | Yes |
Application | rxvt-unicode_project | rxvt-unicode | 9.22 | Yes |
Application | rxvt_project | rxvt | 2.7.10 | Yes |
Operating System | fedoraproject | fedora | 33 | Yes |
Operating System | fedoraproject | fedora | 34 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |