Candidate: CVE-2014-3121 PublicDate: 2014-05-14 00:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3121 Description: rxvt-unicode before 9.20 does not properly handle OSC escape sequences, which allows user-assisted remote attackers to manipulate arbitrary X window properties and execute arbitrary commands. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=746593 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_rxvt-unicode: upstream_rxvt-unicode: released (9.20) lucid_rxvt-unicode: ignored (reached end-of-life) precise_rxvt-unicode: ignored (reached end-of-life) precise/esm_rxvt-unicode: DNE (precise was needed) quantal_rxvt-unicode: ignored (reached end-of-life) saucy_rxvt-unicode: ignored (reached end-of-life) trusty_rxvt-unicode: ignored (reached end-of-life) trusty/esm_rxvt-unicode: DNE (trusty was needed) utopic_rxvt-unicode: not-affected (9.20-1) vivid_rxvt-unicode: not-affected (9.20-1) vivid/stable-phone-overlay_rxvt-unicode: DNE vivid/ubuntu-core_rxvt-unicode: DNE wily_rxvt-unicode: not-affected (9.20-1) xenial_rxvt-unicode: not-affected (9.20-1) yakkety_rxvt-unicode: not-affected (9.20-1) zesty_rxvt-unicode: not-affected (9.20-1) artful_rxvt-unicode: not-affected (9.20-1) bionic_rxvt-unicode: not-affected (9.20-1) cosmic_rxvt-unicode: not-affected (9.20-1) disco_rxvt-unicode: not-affected (9.20-1) devel_rxvt-unicode: not-affected (9.20-1)