OS Command Injection in xterm - CVE-2022-45063
Published: November 11, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation when processing font ops. A remote attacker can trick the victim into opening a specially crafted file and execute arbitrary OS commands on the target system within the vi line-editing mode of Zsh.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
PowerStore T
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Oracle Solaris
SUSE Linux Enterprise Server 12 SP2 BCL
SUSE Linux Enterprise Server 12 SP4 LTSS
SUSE Linux Enterprise Server 12 SP4 ESPOS
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
openEuler
Fedora
xterm
xterm-debugsource
xterm-debuginfo
xterm-bin-debuginfo
xterm-bin
xterm-help
x11-terms/xterm
How to mitigate CVE-2022-45063
PowerStore T - update to 3.5.0.1-2083289
xterm - addressed in versions 308-5.9.1, 330-150000.4.6.1, 330-150200.11.9.1
xterm-debugsource - addressed in versions 308-5.9.1, 330-150000.4.6.1, 330-150200.11.9.1
xterm-debuginfo - update to 308-5.9.1
xterm-bin-debuginfo - addressed in versions 330-150000.4.6.1, 330-150200.11.9.1
xterm-bin - addressed in versions 330-150000.4.6.1, 330-150200.11.9.1
xterm-help - addressed in versions 334-7, 363-6
xterm-debugsource - addressed in versions 334-7, 363-6
xterm-debuginfo - addressed in versions 334-7, 363-6
xterm - addressed in versions 334-7, 363-6
x11-terms/xterm - update to 375
xterm - addressed in versions 375-1.fc35, 375-1.fc36, 375-1.fc37
External References
Related Security Bulletins
- OS command injection in xterm
- Gentoo update for xterm
- Multiple vulnerabilities in Oracle Solaris
- SUSE update for xterm
- SUSE update for xterm
- SUSE update for xterm
- Multiple vulnerabilities in Dell PowerStore Family
- openEuler 22.03 LTS SP3 update for xterm
- openEuler 22.03 LTS SP4 update for xterm
- openEuler 22.03 LTS SP1 update for xterm
- openEuler 20.03 LTS SP4 update for xterm
- Fedora 37 update for xterm
- Fedora 36 update for xterm
- Fedora 35 update for xterm