The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/4xxx/CVE-2022-4170.json",
"cna_assigner": "fedora",
"unresolved_ranges": [
{
"extracted_events": [
{
"last_affected": "rxvt-unicode 9.30"
}
],
"source": "AFFECTED_FIELD"
}
],
"cwe_ids": [
"CWE-74"
]
}{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "9.25"
},
{
"last_affected": "9.26"
}
],
"cpe": [
"cpe:2.3:a:rxvt-unicode_project:rxvt-unicode:9.25:*:*:*:*:*:*:*",
"cpe:2.3:a:rxvt-unicode_project:rxvt-unicode:9.26:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
}