PT-2004-3700 · Lynx+2 · Lynx+2

Mark J. Cox

+1

·

Publicado

1970-01-01

·

Atualizado

2024-02-02

·

CVE-2005-3120

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lynx versions 2.8.6 and earlier
Description The issue is related to multiple vulnerabilities in the Lynx package, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Specifically, a stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escape (ESC) characters.
Recommendations For versions 2.8.6 and earlier, consider disabling the HTrjis function as a temporary workaround until a patch is available. Restrict access to NNTP servers to minimize the risk of exploitation. Avoid using article headers containing Asian characters in the affected Lynx versions until the issue is resolved.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1970
BDU:2015-02648
BDU:2015-04083
BDU:2015-04084
CVE-2005-3120
DSA-1085-1
DSA-874-1
DSA-876-1
RHSA-2005:803
RHSA-2005_803

Produtos afetados

Alt Linux
Lynx
Red Hat