Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

openSUSE Backports: 2022:10222-1 High: rxvt-unicode Security Update

opensuse
Calendar Grey November 30, 2022
Dist Opensuse Esm H88
The latest rxvt-unicode update boosts security, resolves bugs, and optimizes features. Refer to the openSUSE release note.
An update that fixes two vulnerabilities is now available

Description

This update for rxvt-unicode fixes the following issues:

Update to 9.26

- ev_iouring.c was wrongly required during compilation, and wrongly not

packaged.

Update to 9.25 (boo#1186174 CVE-2021-33477)

- for the 17.5th anniversary, and because many distributions seem to

remove rxvt in favour of urxvt, this release resurrects rclock as

urclock.

- add support for systemd socket-based activation - debian bug #917105,

freebsd bug #234276.

- do not destruct perl on exit anymore: this might fail for a variety of

reasons, and takes unneccessary time.

- remove any macros from urxvtperl manpage(s), should fix debian bug

858385.

- the old bg image resources are now provided by the background extension,

and perl is thus required for bg image support. No configuration change

is needed: urxvt autoloads the background ext if any bg image

resource/option is present (for OSC sequences to work you need to enable

it...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP4:

zypper in -t patch openSUSE-2022-10222=1

- openSUSE Backports SLE-15-SP3:

zypper in -t patch openSUSE-2022-10222=1

Package List

- openSUSE Backports SLE-15-SP4 (aarch64 i586 ppc64le s390x x86_64):

rxvt-unicode-9.26-bp154.2.3.1

rxvt-unicode-debuginfo-9.26-bp154.2.3.1

rxvt-unicode-debugsource-9.26-bp154.2.3.1

- openSUSE Backports SLE-15-SP3 (aarch64 i586 ppc64le s390x x86_64):

rxvt-unicode-9.26-bp153.2.3.1

References

https://www.suse.com/security/cve/CVE-2008-1142.html

https://www.suse.com/security/cve/CVE-2021-33477.html

https://bugzilla.suse.com/1186174

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2022:10222-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP3 openSUSE Backports SLE-15-SP4 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here