rxvt-unicode: Buffer overflow rxvt-unicode is vulnerable to a buffer overflow that could lead to the execution of arbitrary code. rxvt-unicode 2005-03-20 2005-03-20 84680 remote 5.3 4.8 5.3

rxvt-unicode is a clone of the well known terminal emulator rxvt.

Rob Holland of the Gentoo Linux Security Audit Team discovered that rxvt-unicode fails to properly check input length.

Successful exploitation would allow an attacker to execute arbitrary code with the permissions of the user running rxvt-unicode.

There is no known workaround at this time.

All rxvt-unicode users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=x11-terms/rxvt-unicode-5.3"
CAN-2005-0764 koon lewk jaervosz