Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-14075 http://linux.oracle.com/errata/ELSA-2025-14075.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: xterm-366-12.el9_6.x86_64.rpm xterm-resize-366-12.el9_6.x86_64.rpm aarch64: xterm-366-12.el9_6.aarch64.rpm xterm-resize-366-12.el9_6.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/xterm-366-12.el9_6.src.rpm Related CVEs: CVE-2022-24130 Description of changes: [366-12] - Rebuild because of build failure - Resolves: RHEL-94699 - Resolves: RHEL-103430 [366-11] - Fix CVE-2022-24130 - Resolves: RHEL-94699 - Resolves: RHEL-103430 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-7427 http://linux.oracle.com/errata/ELSA-2025-7427.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: xterm-366-10.el9_6.x86_64.rpm xterm-resize-366-10.el9_6.x86_64.rpm aarch64: xterm-366-10.el9_6.aarch64.rpm xterm-resize-366-10.el9_6.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//xterm-366-10.el9_6.src.rpm Related CVEs: CVE-2022-45063 Description of changes: [366-10] - Fix CVE-2022-45063 - Resolves: RHEL-87485 _______________________________________________ El-errata mailing list
* bsc#1214282 Cross-References: * CVE-2023-40359 . # Security update for xterm Announcement ID: SUSE-SU-2023:4438-1 Rating: low References: * bsc#1214282 Cross-References: * CVE-2023-40359 CVSS scores: * CVE-2023-40359 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2023-40359 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP4 * Basesystem Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.2 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.2 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for xterm fixes the following issues: * CVE-2023-40359: Fixed reporting characterset names in ReGiS graphics mode. (bsc#1214282) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-4438=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-4438=1 * Basesystem Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-4438=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2023-4438=1 * SUSE Manager Proxy 4.2 zypper in -tpatch SUSE-SLE-Product-SUSE-Manager-Proxy-4.2-2023-4438=1 * SUSE Manager Retail Branch Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.2-2023-4438=1 * SUSE Manager Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.2-2023-4438=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * xterm-bin-330-150200.11.12.1 * xterm-debugsource-330-150200.11.12.1 * xterm-bin-debuginfo-330-150200.11.12.1 * xterm-330-150200.11.12.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * xterm-bin-330-150200.11.12.1 * xterm-debugsource-330-150200.11.12.1 * xterm-bin-debuginfo-330-150200.11.12.1 * xterm-330-150200.11.12.1 * Basesystem Module 15-SP4 (aarch64 ppc64le s390x x86_64) * xterm-bin-330-150200.11.12.1 * xterm-debugsource-330-150200.11.12.1 * xterm-bin-debuginfo-330-150200.11.12.1 * xterm-330-150200.11.12.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * xterm-bin-330-150200.11.12.1 * xterm-debugsource-330-150200.11.12.1 * xterm-bin-debuginfo-330-150200.11.12.1 * xterm-330-150200.11.12.1 * SUSE Manager Proxy 4.2 (x86_64) * xterm-bin-330-150200.11.12.1 * xterm-debugsource-330-150200.11.12.1 * xterm-bin-debuginfo-330-150200.11.12.1 * xterm-330-150200.11.12.1 * SUSE Manager Retail Branch Server 4.2 (x86_64) * xterm-bin-330-150200.11.12.1 * xterm-debugsource-330-150200.11.12.1 * xterm-bin-debuginfo-330-150200.11.12.1 * xterm-330-150200.11.12.1 * SUSE Manager Server 4.2 (ppc64le s390x x86_64) * xterm-bin-330-150200.11.12.1 * xterm-debugsource-330-150200.11.12.1 * xterm-bin-debuginfo-330-150200.11.12.1 * xterm-330-150200.11.12.1 ## References: * https://www.suse.com/security/cve/CVE-2023-40359.html * https://bugzilla.suse.com/show_bug.cgi?id=1214282 . Critical minor severity security patch for xterm targeting CVE-2023-40359 with guidance on installation included.. xterm Security Update, SUSE LowSeverity, Security Patch Instructions. . Severity: Low. LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. SUSE Security Update: Security update for xterm ______________________________________________________________________________ Announcement ID: SUSE-SU-2023:0221-1 Rating: important References: #1205305 Cross-References: CVE-2022-45063 CVSS scores: CVE-2022-45063 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2022-45063 (SUSE): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: SUSE Enterprise Storage 7 SUSE Enterprise Storage 7.1 SUSE Linux Enterprise Desktop 15-SP4 SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS SUSE Linux Enterprise High Performance Computing 15-SP3-ESPOS SUSE Linux Enterprise High Performance Computing 15-SP3-LTSS SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Module for Basesystem 15-SP4 SUSE Linux Enterprise Realtime Extension 15-SP3 SUSE Linux Enterprise Server 15-SP2-LTSS SUSE Linux Enterprise Server 15-SP3-LTSS SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP 15-SP2 SUSE Linux Enterprise Server for SAP 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Manager Proxy 4.2 SUSE Manager Proxy 4.3 SUSE Manager Retail Branch Server 4.2 SUSE Manager Retail Branch Server 4.3 SUSE Manager Server 4.2 SUSE Manager Server 4.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for xtermfixes the following issues: - CVE-2022-45063: Fixed an arbitrary code execution issue under configurations using vi and zsh (bsc#1205305). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2023-221=1 - SUSE Manager Server 4.2: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.2-2023-221=1 - SUSE Manager Retail Branch Server 4.2: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-Server-4.2-2023-221=1 - SUSE Manager Proxy 4.2: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.2-2023-221=1 - SUSE Linux Enterprise Server for SAP 15-SP3: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2023-221=1 - SUSE Linux Enterprise Server for SAP 15-SP2: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2023-221=1 - SUSE Linux Enterprise Server 15-SP3-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2023-221=1 - SUSE Linux Enterprise Server 15-SP2-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2023-221=1 - SUSE Linux Enterprise Realtime Extension 15-SP3: zypper in -t patch SUSE-SLE-Product-RT-15-SP3-2023-221=1 - SUSE Linux Enterprise Module for Basesystem 15-SP4: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-221=1 - SUSE Linux Enterprise High Performance Computing 15-SP3-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2023-221=1 - SUSE Linux Enterprise High Performance Computing 15-SP3-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-ESPOS-2023-221=1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2023-221=1 - SUSE Enterprise Storage 7.1: zypper in -t patch SUSE-Storage-7.1-2023-221=1 - SUSEEnterprise Storage 7: zypper in -t patch SUSE-Storage-7-2023-221=1 Package List: - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): xterm-330-150200.11.9.1 xterm-bin-330-150200.11.9.1 xterm-bin-debuginfo-330-150200.11.9.1 xterm-debugsource-330-150200.11.9.1 - SUSE Manager Server 4.2 (ppc64le s390x x86_64): xterm-330-150200.11.9.1 xterm-bin-330-150200.11.9.1 xterm-bin-debuginfo-330-150200.11.9.1 xterm-debugsource-330-150200.11.9.1 - SUSE Manager Retail Branch Server 4.2 (x86_64): xterm-330-150200.11.9.1 xterm-bin-330-150200.11.9.1 xterm-bin-debuginfo-330-150200.11.9.1 xterm-debugsource-330-150200.11.9.1 - SUSE Manager Proxy 4.2 (x86_64): xterm-330-150200.11.9.1 xterm-bin-330-150200.11.9.1 xterm-bin-debuginfo-330-150200.11.9.1 xterm-debugsource-330-150200.11.9.1 - SUSE Linux Enterprise Server for SAP 15-SP3 (ppc64le x86_64): xterm-330-150200.11.9.1 xterm-bin-330-150200.11.9.1 xterm-bin-debuginfo-330-150200.11.9.1 xterm-debugsource-330-150200.11.9.1 - SUSE Linux Enterprise Server for SAP 15-SP2 (ppc64le x86_64): xterm-330-150200.11.9.1 xterm-bin-330-150200.11.9.1 xterm-bin-debuginfo-330-150200.11.9.1 xterm-debugsource-330-150200.11.9.1 - SUSE Linux Enterprise Server 15-SP3-LTSS (aarch64 ppc64le s390x x86_64): xterm-330-150200.11.9.1 xterm-bin-330-150200.11.9.1 xterm-bin-debuginfo-330-150200.11.9.1 xterm-debugsource-330-150200.11.9.1 - SUSE Linux Enterprise Server 15-SP2-LTSS (aarch64 ppc64le s390x x86_64): xterm-330-150200.11.9.1 xterm-bin-330-150200.11.9.1 xterm-bin-debuginfo-330-150200.11.9.1 xterm-debugsource-330-150200.11.9.1 - SUSE Linux Enterprise Realtime Extension 15-SP3 (x86_64): xterm-330-150200.11.9.1 xterm-bin-330-150200.11.9.1 xterm-bin-debuginfo-330-150200.11.9.1 xterm-debugsource-330-150200.11.9.1 - SUSE Linux Enterprise Modulefor Basesystem 15-SP4 (aarch64 ppc64le s390x x86_64): xterm-330-150200.11.9.1 xterm-bin-330-150200.11.9.1 xterm-bin-debuginfo-330-150200.11.9.1 xterm-debugsource-330-150200.11.9.1 - SUSE Linux Enterprise High Performance Computing 15-SP3-LTSS (aarch64 x86_64): xterm-330-150200.11.9.1 xterm-bin-330-150200.11.9.1 xterm-bin-debuginfo-330-150200.11.9.1 xterm-debugsource-330-150200.11.9.1 - SUSE Linux Enterprise High Performance Computing 15-SP3-ESPOS (aarch64 x86_64): xterm-330-150200.11.9.1 xterm-bin-330-150200.11.9.1 xterm-bin-debuginfo-330-150200.11.9.1 xterm-debugsource-330-150200.11.9.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (aarch64 x86_64): xterm-330-150200.11.9.1 xterm-bin-330-150200.11.9.1 xterm-bin-debuginfo-330-150200.11.9.1 xterm-debugsource-330-150200.11.9.1 - SUSE Enterprise Storage 7.1 (aarch64 x86_64): xterm-330-150200.11.9.1 xterm-bin-330-150200.11.9.1 xterm-bin-debuginfo-330-150200.11.9.1 xterm-debugsource-330-150200.11.9.1 - SUSE Enterprise Storage 7 (aarch64 x86_64): xterm-330-150200.11.9.1 xterm-bin-330-150200.11.9.1 xterm-bin-debuginfo-330-150200.11.9.1 xterm-debugsource-330-150200.11.9.1 References: https://www.suse.com/security/cve/CVE-2022-45063.html https://bugzilla.suse.com/1205305 . A critical patch for xterm resolves a vulnerability related to arbitrary code execution. Check out the new SUSE security bulletin for comprehensive update information.. SUSE Security Update,xterm patch,arbitrary code execution. . Severity: Important. LinuxSecurity.com Team
xterm before patch 375 can enable an RCE under certain conditions. References: - https://bugs.mageia.org/show_bug.cgi?id=31108 - https://www.openwall.com/lists/oss-security/2022/11/10/1 . MGASA-2022-0441 - Updated xterm packages fix security vulnerability Publication date: 27 Nov 2022 URL: https://advisories.mageia.org/MGASA-2022-0441.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-45063 xterm before patch 375 can enable an RCE under certain conditions. References: - https://bugs.mageia.org/show_bug.cgi?id=31108 - https://www.openwall.com/lists/oss-security/2022/11/10/1 - https://lists.fedoraproject.org/archives/list/
Rebase to version 375. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-8cf76a9ceb 2022-11-23 01:19:40.756740 --------------------------------------------------------------------------------Name : xterm Product : Fedora 35 Version : 375 Release : 1.fc35 URL : https://invisible-island.net/xterm/ Summary : Terminal emulator for the X Window System Description : The xterm program is a terminal emulator for the X Window System. It provides DEC VT102 and Tektronix 4014 compatible terminals for programs that can't use the window system directly. --------------------------------------------------------------------------------Update Information: Rebase to version 375 --------------------------------------------------------------------------------ChangeLog: * Mon Oct 31 2022 Tomas Korbar - 375-1 - Rebase to version 375 - Resolves: rhbz#2137784 * Tue Oct 11 2022 Tomas Korbar - 374-1 - Rebase to version 374 - Resolves: rhbz#2133585 * Wed Oct 5 2022 Tomas Korbar - 373-1 - Rebase to version 373 - Resolves: rhbz#2129661 * Sat Jul 23 2022 Fedora Release Engineering - 372-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild * Mon Apr 25 2022 Tomas Korbar - 372-1 - Rebase to version 372 - Resolves: rhbz#2062511 --------------------------------------------------------------------------------References: [ 1 ] Bug #2137784 - xterm-375 is available https://bugzilla.redhat.com/show_bug.cgi?id=2137784 [ 2 ] Bug #2142481 - CVE-2022-45063 xterm: code execution via OSC 50 input sequences [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2142481 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-8cf76a9ceb' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Rebase to version 375. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-af5f1eee2c 2022-11-23 01:15:30.165800 --------------------------------------------------------------------------------Name : xterm Product : Fedora 37 Version : 375 Release : 1.fc37 URL : https://invisible-island.net/xterm/ Summary : Terminal emulator for the X Window System Description : The xterm program is a terminal emulator for the X Window System. It provides DEC VT102 and Tektronix 4014 compatible terminals for programs that can't use the window system directly. --------------------------------------------------------------------------------Update Information: Rebase to version 375 --------------------------------------------------------------------------------ChangeLog: * Mon Oct 31 2022 Tomas Korbar - 375-1 - Rebase to version 375 - Resolves: rhbz#2137784 * Tue Oct 11 2022 Tomas Korbar - 374-1 - Rebase to version 374 - Resolves: rhbz#2133585 * Wed Oct 5 2022 Tomas Korbar - 373-1 - Rebase to version 373 - Resolves: rhbz#2129661 --------------------------------------------------------------------------------References: [ 1 ] Bug #2137784 - xterm-375 is available https://bugzilla.redhat.com/show_bug.cgi?id=2137784 [ 2 ] Bug #2142481 - CVE-2022-45063 xterm: code execution via OSC 50 input sequences [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2142481 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-af5f1eee2c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
A vulnerability has been found in xterm which could allow for arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202211-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: xterm: Arbitrary Code Execution Date: November 22, 2022 Bugs: #880747 ID: 202211-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability has been found in xterm which could allow for arbitrary code execution. Background ========= xterm is a terminal emulator for the X Window system. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 x11-terms/xterm < 375 > = 375 Description ========== xterm does not correctly handle control characters related to OSC 50 font ops sequence handling. Impact ===== The vulnerability allows text written to the terminal to write text to the terminal's command line. If the terminal's shell is zsh running with vi line editing mode, text written to the terminal can also trigger the execution of arbitrary commands via writing ^G to the terminal. Workaround ========= As a workaround, users can disable xterm's usage of OSC 50 sequences by adding the following to the XResources configuration: XTerm*allowFontOps: false Resolution ========= All xterm users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =x11-terms/xterm-375" References ========= [ 1 ] CVE-2022-45063 https://nvd.nist.gov/vuln/detail/CVE-2022-45063 Availability =========== This GLSA and anyupdates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202211-09 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.