CVE-2022-4170 Affecting rxvt-unicode package, versions *


Severity

Recommended
low

Based on Debian security rating.

Threat Intelligence

EPSS
1.33% (86th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN12-RXVTUNICODE-3157500
  • published6 Dec 2022
  • disclosed9 Dec 2022

Introduced: 6 Dec 2022

CVE-2022-4170  (opens in a new tab)

How to fix?

There is no fixed version for Debian:12 rxvt-unicode.

NVD Description

Note: Versions mentioned in the description apply only to the upstream rxvt-unicode package and not the rxvt-unicode package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.

CVSS Scores

version 3.1