CVE Vulnerabilities

CVE-2021-33477

Improper Handling of Exceptional Conditions

Published: May 20, 2021 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q). A response is terminated by a newline.

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

NameVendorStart VersionEnd Version
EtermEterm_project0.9.7 (including)0.9.7 (including)
MrxvtMrxvt_project0.5.4 (including)0.5.4 (including)
Rxvt-unicodeRxvt-unicode_project9.22 (including)9.22 (including)
RxvtRxvt_project2.7.10 (including)2.7.10 (including)
EtermUbuntubionic*
EtermUbuntuesm-apps/bionic*
EtermUbuntuesm-apps/focal*
EtermUbuntuesm-apps/xenial*
EtermUbuntufocal*
EtermUbuntugroovy*
EtermUbuntuhirsute*
EtermUbuntuimpish*
EtermUbuntukinetic*
EtermUbuntutrusty*
EtermUbuntuupstream*
EtermUbuntuxenial*
MrxvtUbuntuesm-apps/xenial*
MrxvtUbuntutrusty*
MrxvtUbuntuxenial*
RxvtUbuntuesm-apps/xenial*
RxvtUbuntutrusty*
RxvtUbuntuupstream*
RxvtUbuntuxenial*
Rxvt-unicodeUbuntubionic*
Rxvt-unicodeUbuntuesm-apps/bionic*
Rxvt-unicodeUbuntuesm-apps/focal*
Rxvt-unicodeUbuntuesm-apps/xenial*
Rxvt-unicodeUbuntufocal*
Rxvt-unicodeUbuntugroovy*
Rxvt-unicodeUbuntuhirsute*
Rxvt-unicodeUbuntuimpish*
Rxvt-unicodeUbuntukinetic*
Rxvt-unicodeUbuntutrusty*
Rxvt-unicodeUbuntuupstream*
Rxvt-unicodeUbuntuxenial*

References