Fix for CVE-2021-33477. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-71556a5722 2021-08-02 01:06:02.549851 --------------------------------------------------------------------------------Name : mrxvt Product : Fedora 33 Version : 0.5.3 Release : 31.fc33 URL : Summary : A lightweight multi-tabbed terminal emulator for X Description : Mrxvt (previously materm) is based on 2.7.11 CVS of rxvt and aterm. --------------------------------------------------------------------------------Update Information: Fix for CVE-2021-33477 --------------------------------------------------------------------------------ChangeLog: * Fri Jul 23 2021 Mamoru TASAKA - 0.5.3-31 - Patch for CVE-2021-33477 (bug 1961794) * Thu Jul 22 2021 Fedora Release Engineering - 0.5.3-30 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild * Tue Jan 26 2021 Fedora Release Engineering - 0.5.3-29 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1961796 - CVE-2021-33477 mrxvt: rxvt-unicode: possible remote code execution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1961796 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-71556a5722' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list
Fix for CVE-2021-33477. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-0d3268fc35 2021-08-02 01:02:57.308545 --------------------------------------------------------------------------------Name : mrxvt Product : Fedora 34 Version : 0.5.3 Release : 31.fc34 URL : Summary : A lightweight multi-tabbed terminal emulator for X Description : Mrxvt (previously materm) is based on 2.7.11 CVS of rxvt and aterm. --------------------------------------------------------------------------------Update Information: Fix for CVE-2021-33477 --------------------------------------------------------------------------------ChangeLog: * Fri Jul 23 2021 Mamoru TASAKA - 0.5.3-31 - Patch for CVE-2021-33477 (bug 1961794) * Thu Jul 22 2021 Fedora Release Engineering - 0.5.3-30 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1961796 - CVE-2021-33477 mrxvt: rxvt-unicode: possible remote code execution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1961796 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-0d3268fc35' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q). A response is terminated by a newline (CVE-2021-33477). References: . MGASA-2021-0358 - Updated rvxt-unicode, mxrvt, eterm packages fix security vulnerability Publication date: 20 Jul 2021 URL: https://advisories.mageia.org/MGASA-2021-0358.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-33477 rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q). A response is terminated by a newline (CVE-2021-33477). References: - https://bugs.mageia.org/show_bug.cgi?id=28939 - https://www.openwall.com/lists/oss-security/2021/05/17/1 - https://www.openwall.com/lists/oss-security/2021/05/17/2 - https://lists.fedoraproject.org/archives/list/
Get the latest Linux and open source security news straight to your inbox.