REDHAT-BUG-2048676: Buffer Overflow
xterm through Patch 370, when Sixel support is enabled, allows attackers to trigger a buffer overflow in setsixel in graphicssixel.c via crafted text.
References:
https://invisible-island.net/xterm/xterm.log.html https://www.openwall.com/lists/oss-security/2022/01/30/2 https://www.openwall.com/lists/oss-security/2022/01/30/3 https://twitter.com/nickblack/status/1487731459398025216
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2048676?
The severity of REDHAT-BUG-2048676 is high due to the potential for a buffer overflow vulnerability.
How do I fix REDHAT-BUG-2048676?
To fix REDHAT-BUG-2048676, update to the latest version of xterm above Patch 370.
What systems are affected by REDHAT-BUG-2048676?
REDHAT-BUG-2048676 affects xterm versions up to and including Patch 370 when Sixel support is enabled.
What type of vulnerability is REDHAT-BUG-2048676?
REDHAT-BUG-2048676 is a buffer overflow vulnerability triggered by crafted text in xterm.
Can REDHAT-BUG-2048676 be exploited remotely?
Yes, REDHAT-BUG-2048676 can be exploited remotely by handling specially crafted text.