VDB
CVE-2022-4170
CVE-2022-4170
PUBLISHED
CVSS 9.800000190734863 CRITICAL
The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.
EPSS 3.36% · 87.6th percentile
Risk Scores
CVSS v3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
3.36%
87.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| rxvt-unicode_project | rxvt-unicode | 9.25, 9.26 |
| fedoraproject | extra_packages_for_enterprise_linux | 8.0 |
| fedoraproject | fedora | 37 |
| n/a | rxvt-unicode | rxvt-unicode 9.30 |
Timeline
- Dec 9, 2022 CVE Published
- Dec 10, 2022 EPSS Score
- Dec 13, 2022 EPSS Score
- Jan 21, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 15, 2023 EPSS Score
- May 27, 2023 EPSS Score
- Jul 7, 2023 EPSS Score
- Sep 29, 2023 EPSS Score
- Nov 10, 2023 EPSS Score
- Dec 22, 2023 EPSS Score
- Feb 2, 2024 EPSS Score