xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-47985 xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 14 May 2025 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/a:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T14:01:31.513Z

Reserved: 2022-11-09T00:00:00

Link: CVE-2022-45063

cve-icon Vulnrichment

Updated: 2024-08-03T14:01:31.513Z

cve-icon NVD

Status : Modified

Published: 2022-11-10T16:15:12.307

Modified: 2024-11-21T07:28:42.460

Link: CVE-2022-45063

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-11-10T00:00:00Z

Links: CVE-2022-45063 - Bugzilla

cve-icon OpenCVE Enrichment

No data.