REDHAT-BUG-2142474: Medium severity xterm vulnerability
xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions.
https://invisible-island.net/xterm/xterm.log.html https://www.openwall.com/lists/oss-security/2022/11/10/1 https://news.ycombinator.com/item?id=33546415 http://www.openwall.com/lists/oss-security/2022/11/10/1 http://www.openwall.com/lists/oss-security/2022/11/10/5
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2142474?
The severity of REDHAT-BUG-2142474 is high due to the potential for code execution through crafted font operations.
How do I fix REDHAT-BUG-2142474?
To fix REDHAT-BUG-2142474, upgrade xterm to version 375 or later.
What versions of xterm are affected by REDHAT-BUG-2142474?
xterm versions prior to 375 are affected by REDHAT-BUG-2142474.
What type of vulnerability is REDHAT-BUG-2142474?
REDHAT-BUG-2142474 is a code execution vulnerability related to font operations.
Which environments are at risk from REDHAT-BUG-2142474?
Linux environments using affected versions of xterm are at risk from REDHAT-BUG-2142474.