rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q). A response is terminated by a newline.
The product does not handle or incorrectly handles an exceptional condition.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Eterm | Eterm_project | 0.9.7 (including) | 0.9.7 (including) |
Mrxvt | Mrxvt_project | 0.5.4 (including) | 0.5.4 (including) |
Rxvt-unicode | Rxvt-unicode_project | 9.22 (including) | 9.22 (including) |
Rxvt | Rxvt_project | 2.7.10 (including) | 2.7.10 (including) |
Eterm | Ubuntu | bionic | * |
Eterm | Ubuntu | groovy | * |
Eterm | Ubuntu | hirsute | * |
Eterm | Ubuntu | impish | * |
Eterm | Ubuntu | kinetic | * |
Eterm | Ubuntu | trusty | * |
Eterm | Ubuntu | xenial | * |
Mrxvt | Ubuntu | trusty | * |
Mrxvt | Ubuntu | xenial | * |
Rxvt | Ubuntu | trusty | * |
Rxvt | Ubuntu | xenial | * |
Rxvt-unicode | Ubuntu | bionic | * |
Rxvt-unicode | Ubuntu | groovy | * |
Rxvt-unicode | Ubuntu | hirsute | * |
Rxvt-unicode | Ubuntu | impish | * |
Rxvt-unicode | Ubuntu | kinetic | * |
Rxvt-unicode | Ubuntu | trusty | * |
Rxvt-unicode | Ubuntu | upstream | * |
Rxvt-unicode | Ubuntu | xenial | * |