rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0...
High severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Feb 2, 2023
Description
Published by the National Vulnerability Database
May 20, 2021
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Feb 2, 2023
rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q). A response is terminated by a newline.
References