oss-sec mailing list archives

Re: rxvt terminal (+bash) remoteish code execution 0day


From: Jakub Wilk <jwilk () jwilk net>
Date: Mon, 17 May 2021 21:28:10 +0200

* def <def () huumeet info>, 2021-05-17, 17:33:
The bug is not technically a 0day for rxvt-unicode and has been known at least since 2017-05-01 when it was discussed publicly in oss-security:

   https://www.openwall.com/lists/oss-security/2017/05/01/20

The issue was quietly fixed in rxvt-unicode upstream in 2017.

Or was it 2019?

http://cvs.schmorp.de/rxvt-unicode/src/command.C?view=log#rev1.585

--
Jakub Wilk


Current thread: