CVE-2022-45872: Input Validation
Published Nov 23, 2022
·Updated
iTerm2 before 3.4.18 mishandles a DECRQSS response.
Affected Software
1 affected component
iTerm2 iTerm2<3.4.18
Event History
Nov 23, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-45872?
CVE-2022-45872 has been rated as a medium severity vulnerability.
2
How do I fix CVE-2022-45872?
To fix CVE-2022-45872, upgrade iTerm2 to version 3.4.18 or later.
3
What is the impact of CVE-2022-45872?
CVE-2022-45872 can lead to potential information disclosure due to mishandling DECRQSS responses in iTerm2.
4
Is CVE-2022-45872 present in my version of iTerm2?
If you are using a version of iTerm2 earlier than 3.4.18, you are vulnerable to CVE-2022-45872.
5
What does DECRQSS refer to in CVE-2022-45872?
DECRQSS refers to a specific terminal response protocol that is mishandled in versions of iTerm2 prior to 3.4.18.