The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.
{
"binaries": [
{
"binary_name": "rxvt-unicode",
"binary_version": "9.21-1build1"
},
{
"binary_name": "rxvt-unicode-256color",
"binary_version": "9.21-1build1"
},
{
"binary_name": "rxvt-unicode-lite",
"binary_version": "9.21-1build1"
},
{
"binary_name": "rxvt-unicode-ml",
"binary_version": "9.21-1build1"
}
]
}{
"binaries": [
{
"binary_name": "aterm",
"binary_version": "9.22-3"
},
{
"binary_name": "aterm-ml",
"binary_version": "9.22-3"
},
{
"binary_name": "rxvt",
"binary_version": "1:2.7.10-7.1+urxvt9.22-3"
},
{
"binary_name": "rxvt-ml",
"binary_version": "1:2.7.10-7.1+urxvt9.22-3"
},
{
"binary_name": "rxvt-unicode",
"binary_version": "9.22-3"
},
{
"binary_name": "rxvt-unicode-256color",
"binary_version": "9.22-3"
},
{
"binary_name": "rxvt-unicode-lite",
"binary_version": "9.22-3"
}
]
}{
"binaries": [
{
"binary_name": "aterm",
"binary_version": "9.22-6build3"
},
{
"binary_name": "aterm-ml",
"binary_version": "9.22-6build3"
},
{
"binary_name": "rxvt",
"binary_version": "1:2.7.10-7.1+urxvt9.22-6build3"
},
{
"binary_name": "rxvt-ml",
"binary_version": "1:2.7.10-7.1+urxvt9.22-6build3"
},
{
"binary_name": "rxvt-unicode",
"binary_version": "9.22-6build3"
},
{
"binary_name": "rxvt-unicode-256color",
"binary_version": "9.22-6build3"
},
{
"binary_name": "rxvt-unicode-lite",
"binary_version": "9.22-6build3"
}
]
}