Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20210517192810.6zus3mumaq6l63zi@jwilk.net>
Date: Mon, 17 May 2021 21:28:10 +0200
From: Jakub Wilk <jwilk@...lk.net>
To: <oss-security@...ts.openwall.com>
Subject: Re: rxvt terminal (+bash) remoteish code execution
 0day

* def <def@...meet.info>, 2021-05-17, 17:33:
>The bug is not technically a 0day for rxvt-unicode and has been known 
>at least since 2017-05-01 when it was discussed publicly in 
>oss-security:
>
>    https://www.openwall.com/lists/oss-security/2017/05/01/20
>
>The issue was quietly fixed in rxvt-unicode upstream in 2017.

Or was it 2019?

http://cvs.schmorp.de/rxvt-unicode/src/command.C?view=log#rev1.585

-- 
Jakub Wilk

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.