MGASA-2014-0202
Dashboard / Vulnerabilities / MGASA-2014-0202
Summary: Updated rxvt-unicode packages fix CVE-2014-3121
Details: Updated rxvt-unicode package fixes security vulnerability: rxvt-unicode (aka urxvt) before 9.20 is vulnerable to a user-assisted arbitrary commands execution issue. This can be exploited by the unprocessed display of certain escape sequences in a crafted text file or program output. Arbitrary command sequences can be constructed using this, and unintentionally executed if used in conjunction with various other escape sequences (CVE-2014-3121).
References: https://advisories.mageia.org/MGASA-2014-0202.html, http://dist.schmorp.de/rxvt-unicode/Changes, http://openwall.com/lists/oss-security/2014/05/01/8, https://bugs.mageia.org/show_bug.cgi?id=13299
Affected packages
Package
Name: rxvt-unicode
Purl: pkg:rpm/mageia/rxvt-unicode?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
