{"id":"UBUNTU-CVE-2022-4170","details":"The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.","modified":"2026-05-20T16:08:15.880353274Z","published":"2022-12-09T18:15:00Z","upstream":["CVE-2022-4170"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-4170"},{"type":"REPORT","url":"https://www.openwall.com/lists/oss-security/2022/12/05/1"},{"type":"REPORT","url":"http://cvs.schmorp.de/rxvt-unicode/src/perl/background?r1=1.105&r2=1.109"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2022-4170"}],"affected":[{"package":{"name":"rxvt-unicode","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/rxvt-unicode?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["9.21-1","9.21-1build1"],"ecosystem_specific":{"binaries":[{"binary_version":"9.21-1build1","binary_name":"rxvt-unicode"},{"binary_name":"rxvt-unicode-256color","binary_version":"9.21-1build1"},{"binary_name":"rxvt-unicode-lite","binary_version":"9.21-1build1"},{"binary_version":"9.21-1build1","binary_name":"rxvt-unicode-ml"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-4170.json"}},{"package":{"name":"rxvt-unicode","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/rxvt-unicode?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["9.22-1build2","9.22-3"],"ecosystem_specific":{"binaries":[{"binary_version":"9.22-3","binary_name":"aterm"},{"binary_version":"9.22-3","binary_name":"aterm-ml"},{"binary_name":"rxvt","binary_version":"1:2.7.10-7.1+urxvt9.22-3"},{"binary_version":"1:2.7.10-7.1+urxvt9.22-3","binary_name":"rxvt-ml"},{"binary_name":"rxvt-unicode","binary_version":"9.22-3"},{"binary_version":"9.22-3","binary_name":"rxvt-unicode-256color"},{"binary_name":"rxvt-unicode-lite","binary_version":"9.22-3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-4170.json"}},{"package":{"name":"rxvt-unicode","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/rxvt-unicode?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["9.22-6build1","9.22-6build2","9.22-6build3"],"ecosystem_specific":{"binaries":[{"binary_version":"9.22-6build3","binary_name":"aterm"},{"binary_name":"aterm-ml","binary_version":"9.22-6build3"},{"binary_name":"rxvt","binary_version":"1:2.7.10-7.1+urxvt9.22-6build3"},{"binary_version":"1:2.7.10-7.1+urxvt9.22-6build3","binary_name":"rxvt-ml"},{"binary_name":"rxvt-unicode","binary_version":"9.22-6build3"},{"binary_name":"rxvt-unicode-256color","binary_version":"9.22-6build3"},{"binary_name":"rxvt-unicode-lite","binary_version":"9.22-6build3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-4170.json"}},{"package":{"name":"rxvt-unicode","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/rxvt-unicode?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["9.22-11","9.26-2","9.30-1","9.30-2","9.30-2build1"],"ecosystem_specific":{"binaries":[{"binary_name":"rxvt-unicode","binary_version":"9.30-2build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-4170.json"}},{"package":{"name":"rxvt-unicode","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/rxvt-unicode?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["9.31-1","9.31-2","9.31-3","9.31-3build1","9.31-3build2"],"ecosystem_specific":{"binaries":[{"binary_name":"rxvt-unicode","binary_version":"9.31-3build2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-4170.json"}},{"package":{"name":"rxvt-unicode","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/rxvt-unicode?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["9.31-3build3"],"ecosystem_specific":{"binaries":[{"binary_name":"rxvt-unicode","binary_version":"9.31-3build3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-4170.json"}},{"package":{"name":"rxvt-unicode","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/rxvt-unicode?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["9.31-3build3","9.31-3build4"],"ecosystem_specific":{"binaries":[{"binary_version":"9.31-3build4","binary_name":"rxvt-unicode"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-4170.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}