CVE-2014-3121
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
14/05/2014
Last modified:
12/04/2025
Description
rxvt-unicode before 9.20 does not properly handle OSC escape sequences, which allows user-assisted remote attackers to manipulate arbitrary X window properties and execute arbitrary commands.
Impact
Base Score 2.0
7.60
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:marc_lehmann:rxvt-unicode:*:*:*:*:*:*:*:* | 9.19 (including) | |
| cpe:2.3:a:marc_lehmann:rxvt-unicode:9.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:marc_lehmann:rxvt-unicode:9.01:*:*:*:*:*:*:* | ||
| cpe:2.3:a:marc_lehmann:rxvt-unicode:9.02:*:*:*:*:*:*:* | ||
| cpe:2.3:a:marc_lehmann:rxvt-unicode:9.05:*:*:*:*:*:*:* | ||
| cpe:2.3:a:marc_lehmann:rxvt-unicode:9.06:*:*:*:*:*:*:* | ||
| cpe:2.3:a:marc_lehmann:rxvt-unicode:9.07:*:*:*:*:*:*:* | ||
| cpe:2.3:a:marc_lehmann:rxvt-unicode:9.08:*:*:*:*:*:*:* | ||
| cpe:2.3:a:marc_lehmann:rxvt-unicode:9.09:*:*:*:*:*:*:* | ||
| cpe:2.3:a:marc_lehmann:rxvt-unicode:9.10:*:*:*:*:*:*:* | ||
| cpe:2.3:a:marc_lehmann:rxvt-unicode:9.11:*:*:*:*:*:*:* | ||
| cpe:2.3:a:marc_lehmann:rxvt-unicode:9.12:*:*:*:*:*:*:* | ||
| cpe:2.3:a:marc_lehmann:rxvt-unicode:9.14:*:*:*:*:*:*:* | ||
| cpe:2.3:a:marc_lehmann:rxvt-unicode:9.15:*:*:*:*:*:*:* | ||
| cpe:2.3:a:marc_lehmann:rxvt-unicode:9.16:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://dist.schmorp.de/rxvt-unicode/Changes
- http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00026.html
- http://lists.opensuse.org/opensuse-updates/2014-06/msg00038.html
- http://seclists.org/oss-sec/2014/q2/204
- http://www.debian.org/security/2014/dsa-2925
- http://www.securityfocus.com/bid/67155
- https://lists.fedoraproject.org/pipermail/package-announce/2014-May/133166.html
- https://lists.fedoraproject.org/pipermail/package-announce/2014-May/133195.html
- http://dist.schmorp.de/rxvt-unicode/Changes
- http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00026.html
- http://lists.opensuse.org/opensuse-updates/2014-06/msg00038.html
- http://seclists.org/oss-sec/2014/q2/204
- http://www.debian.org/security/2014/dsa-2925
- http://www.securityfocus.com/bid/67155
- https://lists.fedoraproject.org/pipermail/package-announce/2014-May/133166.html
- https://lists.fedoraproject.org/pipermail/package-announce/2014-May/133195.html



