xterm-295-3.el7.1

エラータID: AXSA:2021-1554:03

Release date: 
Friday, March 5, 2021 - 07:43
Subject: 
xterm-295-3.el7.1
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

The xterm program is a terminal emulator for the X Window System. It provides DEC VT102 and Tektronix 4014 compatible terminals for programs that can't use the window system directly.

Security Fix(es):

* xterm: crash when processing combining characters (CVE-2021-27135)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2021-27135
xterm through Patch #365 allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted UTF-8 character sequence.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. xterm-295-3.el7.1.src.rpm
    MD5: 7aa586cb6167da96b2d12cdcb4ba924f
    SHA-256: 7ef9e3ea6de477329642efcfe0ad7df61ec94834e2c5b050616c011c831e55cc
    Size: 1.08 MB

Asianux Server 7 for x86_64
  1. xterm-295-3.el7.1.x86_64.rpm
    MD5: b9b586a0690a02e34ef5a413165d7986
    SHA-256: c40a00f6b4ee66a1167c152ded2cbe715f32bf1986572f8651613a8483ef8271
    Size: 454.69 kB