CVE-2022-45063 - CVE House
Back to Database
Status published Critical CVE-2022-45063

xterm before 375 allows code execution via font ops, e.g.,...

Vulnerability Description

xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-45063

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

invisible-island

View all reports →

Affected Software

xterm, fedora
Vulnerable Versions:
0, 35, 36, 37

Timeline

Official Publish: November 10th, 2022
Last Modified: April 8th, 2026
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.