xterm through Patch 370, when Sixel support is enabled, allows attackers to trigger a buffer overflow in set_sixel in graphics_sixel.c via crafted text.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-xtermalma-upgrade-xterm-resize | Aug 20, 2025 | Aug 19, 2025 | |
| Alpine Linux | alpine-linux-upgrade-xterm | Aug 22, 2024 | Jan 31, 2022 | |
| Debian | debian-upgrade-xterm | Feb 9, 2022 | Jan 31, 2022 | |
| Gentoo Linux | gentoo-linux-upgrade-x11-terms-xterm | Aug 16, 2022 | Jan 31, 2022 | |
| Huawei Euleros 2_0_sp8 | huawei-euleros-2_0_sp8-upgrade-xtermhuawei-euleros-2_0_sp8-upgrade-xterm-resize | Apr 26, 2022 | Jan 31, 2022 | |
| Oracle_linux | — | oracle-linux-upgrade-xtermoracle-linux-upgrade-xterm-resize | Aug 20, 2025 | Jan 31, 2022 |
| Redhat_linux | redhat-upgrade-xtermredhat-upgrade-xterm-debuginforedhat-upgrade-xterm-debugsourceredhat-upgrade-xterm-resizeredhat-upgrade-xterm-resize-debuginfo | Jul 11, 2025 | Jan 31, 2022 | |
| Rocky_linux | rocky-upgrade-xtermrocky-upgrade-xterm-debuginforocky-upgrade-xterm-debugsourcerocky-upgrade-xterm-resizerocky-upgrade-xterm-resize-debuginfo | Feb 9, 2026 | Oct 4, 2025 | |
| Suse | — | suse-upgrade-xtermsuse-upgrade-xterm-bin | Nov 14, 2022 | Jan 31, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub