2.6
CVSSv2

CVE-2006-4573

Published: 24/10/2006 Updated: 08/03/2011
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P

Vulnerability Summary

Multiple unspecified vulnerabilities in the "utf8 combining characters handling" (utf8_handle_comb function in encoding.c) in screen prior to 4.0.3 allows user-assisted malicious users to cause a denial of service (crash or hang) via certain UTF8 sequences.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu screen

Vendor Advisories

Debian Bug report logs - #395225 CVE-2006-4573: GNU Screen UTF-8 Character Handling Vulnerabilities Package: screen; Maintainer for screen is Axel Beckert <abe@debianorg>; Source for screen is src:screen (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde> Date: Wed, 25 Oct 2006 18:18:01 UTC Severity: ...
cstone and Rich Felker discovered a programming error in the UTF8 string handling code of “screen” leading to a denial of service If a crafted string was displayed within a screen session, screen would crash or possibly execute arbitrary code ...
cstone and Rich Felker discovered that specially crafted UTF-8 sequences may lead an out of bands memory write when displayed inside the screen terminal multiplexer, allowing denial of service and potentially the execution of arbitrary code For the stable distribution (sarge) this problem has been fixed in version 402-41sarge1 Due to technical ...