CVE-2005-3120
Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escape (ESC) characters.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 23.3%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escape (ESC) characters.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 23.26% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-131
- Affected
- invisible-island/lynx · debian/debian linux
- Source
- security@debian.org
References
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.7/SCOSA-2006.7.txtBroken Link
- ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.47/SCOSA-2005.47.txtBroken Link
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-October/038019.htmlBroken Link, Patch, Vendor Advisory
- http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.htmlBroken Link
- http://secunia.com/advisories/17150Broken Link
- http://secunia.com/advisories/17216Broken Link
- http://secunia.com/advisories/17230Broken Link
- http://secunia.com/advisories/17231Broken Link
- http://secunia.com/advisories/17238Broken Link
- http://secunia.com/advisories/17248Broken Link
- http://secunia.com/advisories/17340Broken Link
- http://secunia.com/advisories/17360Broken Link
- http://secunia.com/advisories/17444Broken Link
- http://secunia.com/advisories/17445Broken Link
- http://secunia.com/advisories/17480Broken Link
- http://secunia.com/advisories/18376Broken Link
- http://secunia.com/advisories/18584Broken Link
- http://secunia.com/advisories/20383Broken Link
- http://securitytracker.com/id?1015065Broken Link, Third Party Advisory, VDB Entry
- http://slackware.com/security/viewer.php?l=slackware-security&y=2005&m=slackware-security.423056Broken Link
- http://support.avaya.com/elmodocs2/security/ASA-2006-010.htmThird Party Advisory
- http://www.debian.org/security/2005/dsa-874Mailing List, Third Party Advisory
- http://www.debian.org/security/2005/dsa-876Mailing List, Third Party Advisory
- http://www.debian.org/security/2006/dsa-1085Mailing List, Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200510-15.xmlThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:186Third Party Advisory
- http://www.novell.com/linux/security/advisories/2005_25_sr.htmlBroken Link
- http://www.openpkg.org/security/OpenPKG-SA-2005.026-lynx.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2005-803.htmlBroken Link, Vendor Advisory
- http://www.securityfocus.com/archive/1/419763/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.