Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

xterm: Multiple Vulnerabilities Regarding to Version 375 #4307

Closed
CamberLoid opened this issue Nov 22, 2022 · 1 comment
Closed

xterm: Multiple Vulnerabilities Regarding to Version 375 #4307

CamberLoid opened this issue Nov 22, 2022 · 1 comment
Labels
security Topic/issue involves a security issue/fixed

Comments

@CamberLoid
Copy link
Member

CVE IDs

CVE-2021-27135, CVE-2022-24130

Other security advisory IDs

Description

CVE-2021-27135: A crafted UTF-8 combining character sequence may allow remote attackers to execute arbitrary code or cause a denial of service.
CVE-2022-24130: Sixel support may allow attackers to trigger a buffer overflow in set_sixel in graphics_sixel.c via crafted text.

Patches

In general, an upgrade to version 375 or after will fix the problem.

PoC(s)

N/A

@CamberLoid CamberLoid added the security Topic/issue involves a security issue/fixed label Nov 22, 2022
CamberLoid added a commit that referenced this issue Nov 23, 2022
* Fixed CVE-2021-27135 and CVE-2022-24130
* Increase output verbosity of beyond file

Signed-off-by: Camber Huang <camber@poi.science>
CamberLoid added a commit that referenced this issue Nov 27, 2022
* Fixed CVE-2021-27135 and CVE-2022-24130
* Increase output verbosity of beyond file

Signed-off-by: Camber Huang <camber@poi.science>
CamberLoid added a commit that referenced this issue Nov 27, 2022
* Fixed CVE-2021-27135 and CVE-2022-24130
* Increase output verbosity of beyond file

Signed-off-by: Camber Huang <camber@poi.science>
@CamberLoid
Copy link
Member Author

Fixed via #4290

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security Topic/issue involves a security issue/fixed
Projects
None yet
Development

No branches or pull requests

1 participant