rxvt-unicode before 9.20 does not properly handle OSC escape sequences, which allows user-assisted remote attackers to manipulate arbitrary X window properties and execute arbitrary commands.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade rxvt-unicode | Aug 30, 2017 | May 13, 2014 |
| Debian | — | Upgrade rxvt-unicode | Jul 30, 2024 | May 14, 2014 |
| Gentoo Linux | — | Upgrade x11-terms/rxvt-unicode. | Oct 30, 2017 | May 13, 2014 |
| Suse | — | Upgrade rxvt-unicode | Dec 18, 2015 | May 13, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub