{"affected":[{"ecosystem_specific":{"binaries":[{"rxvt-unicode":"9.26-bp154.2.3.1"}]},"package":{"ecosystem":"SUSE:Package Hub 15 SP3","name":"rxvt-unicode","purl":"pkg:rpm/suse/rxvt-unicode&distro=SUSE%20Package%20Hub%2015%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"9.26-bp154.2.3.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"rxvt-unicode":"9.26-bp154.2.3.1"}]},"package":{"ecosystem":"SUSE:Package Hub 15 SP4","name":"rxvt-unicode","purl":"pkg:rpm/suse/rxvt-unicode&distro=SUSE%20Package%20Hub%2015%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"9.26-bp154.2.3.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"rxvt-unicode":"9.26-bp154.2.3.1"}]},"package":{"ecosystem":"openSUSE:Leap 15.3","name":"rxvt-unicode","purl":"pkg:rpm/opensuse/rxvt-unicode&distro=openSUSE%20Leap%2015.3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"9.26-bp154.2.3.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"rxvt-unicode":"9.26-bp154.2.3.1"}]},"package":{"ecosystem":"openSUSE:Leap 15.4","name":"rxvt-unicode","purl":"pkg:rpm/opensuse/rxvt-unicode&distro=openSUSE%20Leap%2015.4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"9.26-bp154.2.3.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for rxvt-unicode fixes the following issues:\n\nUpdate to 9.26\n\n- ev_iouring.c was wrongly required during compilation, and wrongly\n  not packaged.\n\nUpdate to 9.25 (boo#1186174 CVE-2021-33477)\n\n- for the 17.5th anniversary, and because many distributions seem to\n  remove rxvt in favour of urxvt, this release resurrects rclock as\n  urclock.\n- add support for systemd socket-based activation - debian bug #917105,\n  freebsd bug #234276.\n- do not destruct perl on exit anymore: this might fail for a variety of\n  reasons, and takes unneccessary time.\n- remove any macros from urxvtperl manpage(s), should fix debian\n  bug 858385.\n- the old bg image resources are now provided by the background\n  extension, and perl is thus required for bg image support. No\n  configuration change is needed: urxvt autoloads the background\n  ext if any bg image resource/option is present (for OSC sequences to\n  work you need to enable it explicity). The old bg image\n  resources are also now deprecated; users are encouraged to\n  switch to the new bg image interface (see man urxvt-background).\n- confirm-paste now checks for any ctlchars, not just newlines.\n- searchable scrollback will now ignore bracketed paste mode sequences\n  (prompted by Daniel Gröber's patch).\n- drop ISO 2022 locale support. ISO 2022 encodings are not supported in\n  POSIX locales and clash with vt100 charset emulation (the luit\n  program can be used as a substitute).\n- perl didn't parse rgba colours specified as an array correctly,\n  only allowing 0 and 100% intensity for each component (this affected\n  fill and tint).\n- when iterating over resources, urxvt will now try to properly handle\n  multipart resources (such as '*background.expr'), for the benefit\n  of autoloading perl extensions.\n- ESC G (query rxvt graphics mode) has been disabled due to security\n  implications. The rxvt graphics mode was removed in rxvt-unicode 1.5,\n  and no programs relying on being able to query the mode are known.\n- work around API change breakage in perl 5.28, based on a patch by\n  Roman Bogorodskiy.\n- improved security: rob nation's (obsolete) graphics mode queries\n  no longer reply with linefeed in secure/default mode.\n- ISO 8613-3 direct colour SGR sequences (patch by Fengguang Wu).\n- xterm focus reporting mode (patch by Daniel Hahler).\n- xterm SGR mouse mode.\n- implement DECRQM. Patch by Přemysl Eric Janouch.\n- add missing color index parameter to OSC 4 response. Patch\n  by Přemysl Eric Janouch.\n- in some window managers, if smart resize was enabled, urxvt\n  erroneously moved the window on font change - awesome bug\n  #532, arch linux bug ##34807 (patch by Uli Schlachter).\n- fix urxvtd crash when using a background expression.\n- properly restore colors when using fading and reverse video\n  is enabled while urxvt is focused and then disabled while it\n  is not focused, or vice versa (patch by Daniel Hahler).\n- fix high memory usage when an extension repeatedly hides and\n  shows an overlay (reported by Marcel Lautenbach).\n- expose priv_modes member and constants to perl extensions\n  (patch by Rastislav Barlik).\n- fix a whole slew of const sillyness, unfortunately forced upon\n  us by ISO C++.\n- update to libecb 0x00010006.\n- disable all thread support in ecb.h as we presumably don't need it.\n- slightly improve Makefile source dependencies.\n- work around bugs in newer Pod::Xhtml versions (flags incorrect formatting codes\n  in xhtml/html sections but does not interpret correct ones).\n- New file: /usr/bin/urclock\n- restore the -256color binaries\n","id":"openSUSE-SU-2022:10222-1","modified":"2022-11-30T08:19:21Z","published":"2022-11-30T08:19:21Z","references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YIRRHCE53YNBLDGNULGNED3XGUMUZDMO/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1186174"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2008-1142"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-33477"}],"related":["CVE-2008-1142","CVE-2021-33477"],"summary":"Security update for rxvt-unicode","upstream":["CVE-2008-1142","CVE-2021-33477"]}