PT-2004-3700 · Lynx+2 · Lynx+2

Mark J. Cox

+1

·

Published

1970-01-01

·

Updated

2024-02-02

·

CVE-2005-3120

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lynx versions 2.8.6 and earlier
Description The issue is related to multiple vulnerabilities in the Lynx package, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Specifically, a stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escape (ESC) characters.
Recommendations For versions 2.8.6 and earlier, consider disabling the HTrjis function as a temporary workaround until a patch is available. Restrict access to NNTP servers to minimize the risk of exploitation. Avoid using article headers containing Asian characters in the affected Lynx versions until the issue is resolved.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1970
BDU:2015-02648
BDU:2015-04083
BDU:2015-04084
CVE-2005-3120
DSA-1085-1
DSA-874-1
DSA-876-1
RHSA-2005:803
RHSA-2005_803

Affected Products

Alt Linux
Lynx
Red Hat