Name
xterm
Version
372
Type
library
Description
xterm is the standard terminal emulator for the X Window System
Licenses
MIT
PURL
-
CPE
cpe:2.3:*:invisible-island:xterm:372:*:*:*:*:*:*:*
Other Versions#
Patches#
#
Title
Author
Resolve
1
snapshot of project "xterm", label xterm-379c
"Thomas E. Dickey" <dickey@invisible-island.net>
CVE-2023-40359
2
snapshot of project "xterm", label xterm-374c
"Thomas E. Dickey" <dickey@invisible-island.net>
CVE-2022-45063
3
Add configure time check for setsid
Khem Raj <raj.khem@gmail.com>
Vulnerabilities#
Name
Analysis
Description
Patched
xterm before 380 supports ReGIS reporting for character-set names even if they have unexpected characters (i.e., neither alphanumeric nor underscore), aka a pointer/overflow issue. This can only occur for xterm installations that are configured at compile time to use a certain experimental feature.
Patched
xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions.