CVE-2021-33477

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-33477
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-33477.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-33477
Related
Published
2021-05-20T20:15:07Z
Modified
2024-09-18T03:15:27.749876Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q). A response is terminated by a newline.

References

Affected packages

Alpine:v3.10 / mrxvt

Package

Name
mrxvt
Purl
pkg:apk/alpine/mrxvt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.4-r8

Affected versions

0.*

0.5.4-r0
0.5.4-r1
0.5.4-r2
0.5.4-r3
0.5.4-r4
0.5.4-r5
0.5.4-r6
0.5.4-r7

Alpine:v3.10 / rxvt-unicode

Package

Name
rxvt-unicode
Purl
pkg:apk/alpine/rxvt-unicode?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.22-r7

Affected versions

9.*

9.11-r0
9.15-r0
9.18-r0
9.18-r1
9.18-r2
9.18-r3
9.19-r0
9.20-r0
9.20-r1
9.21-r0
9.21-r1
9.21-r2
9.21-r3
9.21-r4
9.22-r0
9.22-r1
9.22-r2
9.22-r3
9.22-r4
9.22-r5
9.22-r6

Alpine:v3.11 / mrxvt

Package

Name
mrxvt
Purl
pkg:apk/alpine/mrxvt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.4-r8

Affected versions

0.*

0.5.4-r0
0.5.4-r1
0.5.4-r2
0.5.4-r3
0.5.4-r4
0.5.4-r5
0.5.4-r6
0.5.4-r7

Alpine:v3.11 / rxvt-unicode

Package

Name
rxvt-unicode
Purl
pkg:apk/alpine/rxvt-unicode?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.22-r8

Affected versions

9.*

9.11-r0
9.15-r0
9.18-r0
9.18-r1
9.18-r2
9.18-r3
9.19-r0
9.20-r0
9.20-r1
9.21-r0
9.21-r1
9.21-r2
9.21-r3
9.21-r4
9.22-r0
9.22-r1
9.22-r2
9.22-r3
9.22-r4
9.22-r5
9.22-r6
9.22-r7

Debian:11 / eterm

Package

Name
eterm
Purl
pkg:deb/debian/eterm?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.6-6.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / eterm

Package

Name
eterm
Purl
pkg:deb/debian/eterm?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.6-6.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:11 / rxvt-unicode

Package

Name
rxvt-unicode
Purl
pkg:deb/debian/rxvt-unicode?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.22-11

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / rxvt-unicode

Package

Name
rxvt-unicode
Purl
pkg:deb/debian/rxvt-unicode?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.22-11

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / rxvt-unicode

Package

Name
rxvt-unicode
Purl
pkg:deb/debian/rxvt-unicode?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.22-11

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/exg/rxvt-unicode

Affected ranges

Type
GIT
Repo
https://github.com/exg/rxvt-unicode
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

rxvt-unicode-1.*

rxvt-unicode-1.2
rxvt-unicode-1.3
rxvt-unicode-1.9

rxvt-unicode-2.*

rxvt-unicode-2.0
rxvt-unicode-2.1
rxvt-unicode-2.2
rxvt-unicode-2.3
rxvt-unicode-2.4
rxvt-unicode-2.5
rxvt-unicode-2.7
rxvt-unicode-2.8

rxvt-unicode-3.*

rxvt-unicode-3.0
rxvt-unicode-3.2
rxvt-unicode-3.3
rxvt-unicode-3.4
rxvt-unicode-3.5
rxvt-unicode-3.6
rxvt-unicode-3.7
rxvt-unicode-3.8

rxvt-unicode-4.*

rxvt-unicode-4.0
rxvt-unicode-4.1
rxvt-unicode-4.2
rxvt-unicode-4.3
rxvt-unicode-4.4
rxvt-unicode-4.6
rxvt-unicode-4.7
rxvt-unicode-4.8
rxvt-unicode-4.9

rxvt-unicode-5.*

rxvt-unicode-5.0
rxvt-unicode-5.1
rxvt-unicode-5.2
rxvt-unicode-5.3
rxvt-unicode-5.4
rxvt-unicode-5.5
rxvt-unicode-5.7
rxvt-unicode-5.8
rxvt-unicode-5.9

rxvt-unicode-6.*

rxvt-unicode-6.0
rxvt-unicode-6.1
rxvt-unicode-6.2
rxvt-unicode-6.3

rxvt-unicode-7.*

rxvt-unicode-7.0
rxvt-unicode-7.1
rxvt-unicode-7.2
rxvt-unicode-7.3
rxvt-unicode-7.3a
rxvt-unicode-7.4
rxvt-unicode-7.5
rxvt-unicode-7.6
rxvt-unicode-7.7
rxvt-unicode-7.8
rxvt-unicode-7.9

rxvt-unicode-8.*

rxvt-unicode-8.0
rxvt-unicode-8.1
rxvt-unicode-8.2
rxvt-unicode-8.3
rxvt-unicode-8.4
rxvt-unicode-8.5a
rxvt-unicode-8.6
rxvt-unicode-8.7
rxvt-unicode-8.8
rxvt-unicode-8.9

rxvt-unicode-9.*

rxvt-unicode-9.0
rxvt-unicode-9.01
rxvt-unicode-9.02
rxvt-unicode-9.05
rxvt-unicode-9.06
rxvt-unicode-9.07
rxvt-unicode-9.09
rxvt-unicode-9.10
rxvt-unicode-9.11
rxvt-unicode-9.12
rxvt-unicode-9.14
rxvt-unicode-9.15
rxvt-unicode-9.16
rxvt-unicode-9.17
rxvt-unicode-9.18
rxvt-unicode-9.19
rxvt-unicode-9.20
rxvt-unicode-9.21
rxvt-unicode-9.22