PT-2000-1417 · Rxvt+2 · Rxvt+2

Published

2000-06-01

·

Updated

2024-06-10

·

CVE-2000-0476

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions xterm versions (affected versions not specified) Eterm versions (affected versions not specified) rxvt versions (affected versions not specified)
Description The issue allows an attacker to cause a denial of service by embedding certain escape characters, which force the window to be resized.
Recommendations For xterm, consider restricting the use of escape characters to minimize the risk of exploitation. For Eterm, avoid using the affected escape characters until the issue is resolved. For rxvt, as a temporary workaround, consider disabling the resizing feature based on escape characters until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2000-0476

Affected Products

Eterm
Rxvt
Xterm