Description
In Zutty before 0.13, DECRQSS in text written to the terminal can achieve arbitrary code execution.
References
https://bugs.gentoo.org/868495
ExploitIssue TrackingPatchThird Party Advisory
https://github.com/tomszilagyi/zutty/commit/bde7458c60a7bafe08bbeaafbf861eb865edfa38
PatchThird Party Advisory
https://github.com/tomszilagyi/zutty/compare/0.12...0.13
PatchRelease NotesThird Party Advisory
https://security.gentoo.org/glsa/202209-25
Third Party Advisory
https://bugs.gentoo.org/868495
ExploitIssue TrackingPatchThird Party Advisory
https://github.com/tomszilagyi/zutty/commit/bde7458c60a7bafe08bbeaafbf861eb865edfa38
PatchThird Party Advisory
https://github.com/tomszilagyi/zutty/compare/0.12...0.13
PatchRelease NotesThird Party Advisory
https://security.gentoo.org/glsa/202209-25
Third Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8 · Critical
Information
Source identifier
Vulnerability status
Modified
Published
2022-09-20T16:15:10.690Z
3 years agoLast modified
2025-05-29T12:15:30.140Z
7 months ago