Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-4170


The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.


Published

2022-12-09T18:15:20.327

Last Modified

2025-04-14T18:15:25.293

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-74
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application rxvt-unicode_project rxvt-unicode 9.25 Yes
Application rxvt-unicode_project rxvt-unicode 9.26 Yes
Application fedoraproject extra_packages_for_enterprise_linux 8.0 Yes
Operating System fedoraproject fedora 37 Yes

References