{"id":"CVE-2022-4170","details":"The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.","modified":"2026-08-12T03:51:41.064146565Z","published":"2022-12-09T00:00:00Z","related":["openSUSE-SU-2023:0306-1","openSUSE-SU-2024:13323-1"],"database_specific":{"cna_assigner":"fedora","cwe_ids":["CWE-74"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/4xxx/CVE-2022-4170.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"rxvt-unicode 9.30"},{"last_affected":"rxvt-unicode 9.30"}]}]},"references":[{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2022/12/05/1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/4xxx/CVE-2022-4170.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-4170"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202310-20"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2151597"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/exg/rxvt-unicode","events":[{"introduced":"4cbc689ec6ff9174e2d28c12f5777e224b2c79ba"},{"last_affected":"963a50ca86662feb39951be3cd601a305aef6a8a"}],"database_specific":{"source":"CPE_STRING","cpe":["cpe:2.3:a:rxvt-unicode_project:rxvt-unicode:9.25:*:*:*:*:*:*:*","cpe:2.3:a:rxvt-unicode_project:rxvt-unicode:9.26:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"9.25"},{"last_affected":"9.25"},{"introduced":"9.26"},{"last_affected":"9.26"}]}}],"versions":["9.25","9.26","rxvt-unicode-9.26","rxvt-unicode-9.25"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-4170.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}