CVE-2021-33477

Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-33477.json
Published
2021-05-20T20:15:00Z
Modified
2023-08-31T02:29:12.298758Z
Details

rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q). A response is terminated by a newline.

References

Affected packages

Alpine:v3.10 / mrxvt

Source Details

Package Name
mrxvt

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
0.5.4-r8

Alpine:v3.10 / rxvt-unicode

Source Details

Package Name
rxvt-unicode

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
9.22-r7

Affected versions

9.*

9.11-r0
9.15-r0
9.18-r0
9.18-r1
9.18-r2
9.18-r3
9.19-r0
9.20-r0
9.20-r1
9.21-r0
9.21-r1
9.21-r2
9.21-r3
9.21-r4
9.22-r4

Alpine:v3.11 / mrxvt

Source Details

Package Name
mrxvt

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
0.5.4-r8

Alpine:v3.11 / rxvt-unicode

Source Details

Package Name
rxvt-unicode

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
9.22-r8

Affected versions

9.*

9.11-r0
9.15-r0
9.18-r0
9.18-r1
9.18-r2
9.18-r3
9.19-r0
9.20-r0
9.20-r1
9.21-r0
9.21-r1
9.21-r2
9.21-r3
9.21-r4
9.22-r4