INFSA-2025:7427: xterm security update

Information about definition

Identificator: INFSA-2025:7427

Type: security

Release date: 2025-06-10 08:43:28 UTC

Information about package

The xterm program is a terminal emulator for the X Window System. It provides DEC VT102 and Tektronix 4014 compatible terminals for programs that can't use the window system directly.

Vulnerabilities description

  • CVE-2022-45063

    xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
no information 7.4 no information
Critical, important, moderate, low

Updated packages