Vulnerability Name:

CVE-2014-3121 (CCN-92941)

Assigned:2014-04-26
Published:2014-04-26
Updated:2017-12-29
Summary:rxvt-unicode before 9.20 does not properly handle OSC escape sequences, which allows user-assisted remote attackers to manipulate arbitrary X window properties and execute arbitrary commands.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.6 High (CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C)
5.6 Medium (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-78
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2014-3121

Source: CONFIRM
Type: UNKNOWN
http://dist.schmorp.de/rxvt-unicode/Changes

Source: SUSE
Type: UNKNOWN
SUSE-SU-2014:0838

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2014:0814

Source: CCN
Type: oss-security Mailing List, Wed 30 Apr 2014
CVE request: rxvt-unicode user-assisted arbitrary commands execution

Source: MLIST
Type: UNKNOWN
[oss-security] 20140430 CVE request: rxvt-unicode user-assisted arbitrary commands execution

Source: CCN
Type: rxvt-unicode Web page
rxvt-unicode

Source: DEBIAN
Type: UNKNOWN
DSA-2925

Source: BID
Type: UNKNOWN
67155

Source: CCN
Type: BID-67155
RXVT-Unicode CVE-2014-3121 Remote Command Execution Vulnerability

Source: XF
Type: UNKNOWN
rxvtunicode-cve20143121-command-exec(92941)

Source: FEDORA
Type: UNKNOWN
FEDORA-2014-5938

Source: FEDORA
Type: UNKNOWN
FEDORA-2014-5939

Vulnerable Configuration:Configuration 1:
  • cpe:/a:marc_lehmann:rxvt-unicode:9.0:*:*:*:*:*:*:*
  • OR cpe:/a:marc_lehmann:rxvt-unicode:9.01:*:*:*:*:*:*:*
  • OR cpe:/a:marc_lehmann:rxvt-unicode:9.02:*:*:*:*:*:*:*
  • OR cpe:/a:marc_lehmann:rxvt-unicode:9.05:*:*:*:*:*:*:*
  • OR cpe:/a:marc_lehmann:rxvt-unicode:9.06:*:*:*:*:*:*:*
  • OR cpe:/a:marc_lehmann:rxvt-unicode:9.07:*:*:*:*:*:*:*
  • OR cpe:/a:marc_lehmann:rxvt-unicode:9.08:*:*:*:*:*:*:*
  • OR cpe:/a:marc_lehmann:rxvt-unicode:9.09:*:*:*:*:*:*:*
  • OR cpe:/a:marc_lehmann:rxvt-unicode:9.10:*:*:*:*:*:*:*
  • OR cpe:/a:marc_lehmann:rxvt-unicode:9.11:*:*:*:*:*:*:*
  • OR cpe:/a:marc_lehmann:rxvt-unicode:9.12:*:*:*:*:*:*:*
  • OR cpe:/a:marc_lehmann:rxvt-unicode:9.14:*:*:*:*:*:*:*
  • OR cpe:/a:marc_lehmann:rxvt-unicode:9.15:*:*:*:*:*:*:*
  • OR cpe:/a:marc_lehmann:rxvt-unicode:9.16:*:*:*:*:*:*:*
  • OR cpe:/a:marc_lehmann:rxvt-unicode:9.17:*:*:*:*:*:*:*
  • OR cpe:/a:marc_lehmann:rxvt-unicode:9.18:*:*:*:*:*:*:*
  • OR cpe:/a:marc_lehmann:rxvt-unicode:*:*:*:*:*:*:*:* (Version <= 9.19)

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20143121
    V
    CVE-2014-3121
    2022-06-30
    oval:org.opensuse.security:def:113417
    P
    rxvt-unicode-9.22-1.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:106819
    P
    rxvt-unicode-9.22-1.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:26128
    P
    Security update for postgresql13 (Moderate)
    2021-09-16
    oval:org.opensuse.security:def:55948
    P
    Security update for transfig (Moderate)
    2021-09-16
    oval:org.opensuse.security:def:26116
    P
    Security update for apache2 (Important)
    2021-09-02
    oval:org.opensuse.security:def:26117
    P
    Security update for xen (Important)
    2021-09-02
    oval:org.opensuse.security:def:56060
    P
    Security update for openssl (Important)
    2021-08-24
    oval:org.opensuse.security:def:57491
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-08-20
    oval:org.opensuse.security:def:36567
    P
    rxvt-unicode-9.05-1.19.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:56022
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:54780
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP2) (Important)
    2021-03-17
    oval:org.opensuse.security:def:55856
    P
    Security update for python-cryptography (Important)
    2021-03-02
    oval:org.opensuse.security:def:55297
    P
    Security update for java-1_8_0-openjdk (Moderate)
    2021-02-19
    oval:org.opensuse.security:def:26192
    P
    Security update for php72 (Important)
    2021-02-17
    oval:org.opensuse.security:def:55191
    P
    Security update for dovecot22 (Important)
    2021-01-04
    oval:org.opensuse.security:def:26795
    P
    opie on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26440
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:27017
    P
    puppet on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27721
    P
    Security update for dbus-1
    2020-12-01
    oval:org.opensuse.security:def:28793
    P
    Security update for libX11 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55018
    P
    syslog-service on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26834
    P
    tomcat6 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26441
    P
    Security update for phpMyAdmin (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27070
    P
    NetworkManager on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27805
    P
    Security update for libpng12-0 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28828
    P
    Security update for rxvt-unicode
    2020-12-01
    oval:org.opensuse.security:def:56141
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26320
    P
    Security update to go1.4 (Low)
    2020-12-01
    oval:org.opensuse.security:def:26848
    P
    yast2-core on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26452
    P
    Security update for phpMyAdmin (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27119
    P
    evolution-data-server on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27378
    P
    build on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27956
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:57417
    P
    Security update for OpenSSL
    2020-12-01
    oval:org.opensuse.security:def:26401
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:26892
    P
    expat on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26516
    P
    NetworkManager on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27158
    P
    kdelibs3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27379
    P
    bytefx-data-mysql on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28009
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55463
    P
    Security update for xfsprogs (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26458
    P
    Security update for phpMyAdmin (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27530
    P
    pam-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26644
    P
    tar on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27172
    P
    libadns1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27390
    P
    dhcp-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28058
    P
    Security update for dhcp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54617
    P
    libusbmuxd4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55748
    P
    Recommended update for libksba (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26542
    P
    evolution-data-server on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27565
    P
    rxvt-unicode on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26725
    P
    kdelibs3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27216
    P
    libsnmp15-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27454
    P
    libjasper-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28097
    P
    Security update for gimp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54618
    P
    libvdpau1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26693
    P
    evolution-data-server on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26782
    P
    man on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27854
    P
    Security update for php53 (Important)
    2020-12-01
    oval:org.opensuse.security:def:27582
    P
    xorg-x11-libX11-devel-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28111
    P
    Security update for glibc (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54640
    P
    openvpn on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26746
    P
    libfreebl3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26866
    P
    apache2-mod_security2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27889
    P
    Security update for rxvt-unicode
    2020-12-01
    oval:org.opensuse.security:def:27664
    P
    Security update for rubygem-actionpack-2_3
    2020-12-01
    oval:org.opensuse.security:def:28155
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.mitre.oval:def:25874
    P
    SUSE-SU-2014:0838-1 -- Security update for rxvt-unicode
    2014-09-15
    oval:org.mitre.oval:def:24877
    P
    DSA-2925-1 rxvt-unicode - security update
    2014-07-21
    oval:org.opensuse.security:def:80125
    P
    Security update for rxvt-unicode
    2014-06-20
    oval:com.ubuntu.xenial:def:201431210000000
    V
    CVE-2014-3121 on Ubuntu 16.04 LTS (xenial) - medium.
    2014-05-14
    oval:com.ubuntu.disco:def:201431210000000
    V
    CVE-2014-3121 on Ubuntu 19.04 (disco) - medium.
    2014-05-14
    oval:com.ubuntu.bionic:def:201431210000000
    V
    CVE-2014-3121 on Ubuntu 18.04 LTS (bionic) - medium.
    2014-05-14
    oval:com.ubuntu.artful:def:20143121000
    V
    CVE-2014-3121 on Ubuntu 17.10 (artful) - medium.
    2014-05-13
    oval:com.ubuntu.trusty:def:20143121000
    V
    CVE-2014-3121 on Ubuntu 14.04 LTS (trusty) - medium.
    2014-05-13
    oval:com.ubuntu.bionic:def:20143121000
    V
    CVE-2014-3121 on Ubuntu 18.04 LTS (bionic) - medium.
    2014-05-13
    oval:com.ubuntu.xenial:def:20143121000
    V
    CVE-2014-3121 on Ubuntu 16.04 LTS (xenial) - medium.
    2014-05-13
    oval:com.ubuntu.cosmic:def:201431210000000
    V
    CVE-2014-3121 on Ubuntu 18.10 (cosmic) - medium.
    2014-05-13
    oval:com.ubuntu.cosmic:def:20143121000
    V
    CVE-2014-3121 on Ubuntu 18.10 (cosmic) - medium.
    2014-05-13
    oval:com.ubuntu.precise:def:20143121000
    V
    CVE-2014-3121 on Ubuntu 12.04 LTS (precise) - medium.
    2014-05-13
    BACK
    marc_lehmann rxvt-unicode 9.0
    marc_lehmann rxvt-unicode 9.01
    marc_lehmann rxvt-unicode 9.02
    marc_lehmann rxvt-unicode 9.05
    marc_lehmann rxvt-unicode 9.06
    marc_lehmann rxvt-unicode 9.07
    marc_lehmann rxvt-unicode 9.08
    marc_lehmann rxvt-unicode 9.09
    marc_lehmann rxvt-unicode 9.10
    marc_lehmann rxvt-unicode 9.11
    marc_lehmann rxvt-unicode 9.12
    marc_lehmann rxvt-unicode 9.14
    marc_lehmann rxvt-unicode 9.15
    marc_lehmann rxvt-unicode 9.16
    marc_lehmann rxvt-unicode 9.17
    marc_lehmann rxvt-unicode 9.18
    marc_lehmann rxvt-unicode *