VDB
CVE-2022-4170
CVE-2022-4170
PUBLISHED
CVSS 9.800000190734863 CRITICAL
The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.
EPSS 2.06% · 79.5th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
2.06%
79.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| rxvt-unicode_project | rxvt-unicode | 9.25, 9.26 |
| fedoraproject | extra_packages_for_enterprise_linux | 8.0 |
| fedoraproject | fedora | 37 |
| n/a | rxvt-unicode | rxvt-unicode 9.30 |
Timeline
- Dec 9, 2022 CVE Published
- Dec 10, 2022 EPSS Score
- Dec 13, 2022 EPSS Score
- Jan 21, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 15, 2023 EPSS Score
- May 27, 2023 EPSS Score
- Jul 8, 2023 EPSS Score
- Aug 19, 2023 EPSS Score
- Nov 11, 2023 EPSS Score
- Dec 23, 2023 EPSS Score
- Feb 3, 2024 EPSS Score