10
CVSSv2

CVE-2003-0972

Published: 15/12/2003 Updated: 18/10/2016
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Integer signedness error in ansi.c for GNU screen 4.0.1 and previous versions, and 3.9.15 and previous versions, allows local users to execute arbitrary code via a large number of ";" (semicolon) characters in escape sequences, which leads to a buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu screen 3.9.15

gnu screen 3.9.4

gnu screen 3.9.11

gnu screen 3.9.13

gnu screen 3.9.8

gnu screen 3.9.9

gnu screen 3.9.10

gnu screen 4.0.1

Vendor Advisories

Timo Sirainen reported a vulnerability in screen, a terminal multiplexor with VT100/ANSI terminal emulation, that can lead an attacker to gain group utmp privileges For the stable distribution (woody) this problem has been fixed in version 3911-5woody1 For the unstable distribution (sid) this problem has been fixed in version 402-01 We reco ...