The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade rxvt-unicode | Aug 22, 2024 | Dec 9, 2022 |
| Debian | — | No solution existsUpgrade rxvt-unicode | May 15, 2025 | Dec 9, 2022 |
| Freebsd | — | Upgrade rxvt-unicode | Jan 9, 2023 | Jan 3, 2023 |
| Gentoo Linux | — | Upgrade x11-terms/rxvt-unicode. | Oct 31, 2023 | Dec 9, 2022 |
| Suse | — | Upgrade rxvt-unicode | Oct 23, 2023 | Dec 9, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub