VulnerabilityModified
CVE-2022-24130
xterm through Patch 370, when Sixel support is enabled, allows attackers to trigger a buffer overflow in set_sixel in graphics_sixel.c via crafted text.
MEDIUM 5.5EPSS 1.69%
Does this matter?
Lower severity and a low EPSS score (1.69%). Track it; it rarely justifies an emergency change on its own.
Description
xterm through Patch 370, when Sixel support is enabled, allows attackers to trigger a buffer overflow in set_sixel in graphics_sixel.c via crafted text.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 1.69% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120
- Affected
- invisible-island/xterm · debian/debian linux · fedoraproject/fedora
- Source
- cve@mitre.org
References
- https://invisible-island.net/xterm/xterm.log.htmlPatch, Release Notes, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/02/msg00007.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BP5Y4O7WBNLV24D22E6LE7RQFYOUVD2U/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4CWYYEBT6AJRJBBQU2KLUOQDHRM7WAV/
- https://security.gentoo.org/glsa/202208-22Third Party Advisory
- https://twitter.com/nickblack/status/1487731459398025216Exploit, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/01/30/2Exploit, Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/01/30/3Exploit, Mailing List, Third Party Advisory
- https://invisible-island.net/xterm/xterm.log.htmlPatch, Release Notes, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/02/msg00007.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BP5Y4O7WBNLV24D22E6LE7RQFYOUVD2U/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4CWYYEBT6AJRJBBQU2KLUOQDHRM7WAV/
- https://security.gentoo.org/glsa/202208-22Third Party Advisory
- https://twitter.com/nickblack/status/1487731459398025216Exploit, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/01/30/2Exploit, Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/01/30/3Exploit, Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.