4
CVSSv2

CVE-2012-2738

Published: 22/07/2012 Updated: 26/10/2016
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

The VteTerminal in gnome-terminal (vte) prior to 0.32.2 allows remote authenticated users to cause a denial of service (long loop and CPU consumption) via an escape sequence with a large repeat count value.

Vulnerable Product Search on Vulmon Subscribe to Product

nalin dahyabhai vte 0.31.0

nalin dahyabhai vte 0.30.1

nalin dahyabhai vte 0.27.90

nalin dahyabhai vte 0.27.5

nalin dahyabhai vte 0.26.1

nalin dahyabhai vte 0.26.0

nalin dahyabhai vte 0.25.91

nalin dahyabhai vte 0.23.2

nalin dahyabhai vte 0.23.1

nalin dahyabhai vte 0.21.7

nalin dahyabhai vte 0.20.5

nalin dahyabhai vte 0.17.4

nalin dahyabhai vte 0.29.0

nalin dahyabhai vte 0.28.2

nalin dahyabhai vte 0.27.2

nalin dahyabhai vte 0.27.1

nalin dahyabhai vte 0.24.1

nalin dahyabhai vte 0.24.0

nalin dahyabhai vte 0.22.3

nalin dahyabhai vte 0.22.2

nalin dahyabhai vte 0.21.3

nalin dahyabhai vte 0.21.2

nalin dahyabhai vte 0.19.3

nalin dahyabhai vte 0.19.2

nalin dahyabhai vte 0.14.2

nalin dahyabhai vte 0.12.2

nalin dahyabhai vte 0.16.8

nalin dahyabhai vte 0.16.7

nalin dahyabhai vte 0.15.6

nalin dahyabhai vte 0.15.5

nalin dahyabhai vte 0.13.7

nalin dahyabhai vte 0.13.6

nalin dahyabhai vte 0.12.1

nalin dahyabhai vte 0.12.0

nalin dahyabhai vte 0.11.20

nalin dahyabhai vte 0.11.13

nalin dahyabhai vte 0.11.12

nalin dahyabhai vte 0.11.5

nalin dahyabhai vte 0.11.4

nalin dahyabhai vte 0.10.26

nalin dahyabhai vte 0.10.25

nalin dahyabhai vte 0.10.16

nalin dahyabhai vte 0.10.15

nalin dahyabhai vte 0.10.8

nalin dahyabhai vte 0.10.7

nalin dahyabhai vte 0.9.2

nalin dahyabhai vte 0.9.0

nalin dahyabhai vte

nalin dahyabhai vte 0.32.0

nalin dahyabhai vte 0.28.1

nalin dahyabhai vte 0.28.0

nalin dahyabhai vte 0.27.0

nalin dahyabhai vte 0.26.2

nalin dahyabhai vte 0.23.5

nalin dahyabhai vte 0.23.4

nalin dahyabhai vte 0.22.1

nalin dahyabhai vte 0.22.0

nalin dahyabhai vte 0.21.1

nalin dahyabhai vte 0.20.4

nalin dahyabhai vte 0.19.1

nalin dahyabhai vte 0.17.3

nalin dahyabhai vte 0.11.21

nalin dahyabhai vte 0.16.13

nalin dahyabhai vte 0.16.6

nalin dahyabhai vte 0.16.5

nalin dahyabhai vte 0.16.4

nalin dahyabhai vte 0.15.4

nalin dahyabhai vte 0.15.3

nalin dahyabhai vte 0.13.5

nalin dahyabhai vte 0.13.4

nalin dahyabhai vte 0.11.19

nalin dahyabhai vte 0.11.18

nalin dahyabhai vte 0.11.11

nalin dahyabhai vte 0.11.10

nalin dahyabhai vte 0.11.3

nalin dahyabhai vte 0.11.2

nalin dahyabhai vte 0.10.23

nalin dahyabhai vte 0.10.22

nalin dahyabhai vte 0.10.14

nalin dahyabhai vte 0.10.13

nalin dahyabhai vte 0.10.6

nalin dahyabhai vte 0.10.5

nalin dahyabhai vte 0.21.6

nalin dahyabhai vte 0.20.3

nalin dahyabhai vte 0.20.2

nalin dahyabhai vte 0.20.1

nalin dahyabhai vte 0.17.2

nalin dahyabhai vte 0.17.1

nalin dahyabhai vte 0.16.12

nalin dahyabhai vte 0.16.11

nalin dahyabhai vte 0.16.3

nalin dahyabhai vte 0.16.2

nalin dahyabhai vte 0.15.2

nalin dahyabhai vte 0.15.1

nalin dahyabhai vte 0.13.3

nalin dahyabhai vte 0.13.2

nalin dahyabhai vte 0.11.17

nalin dahyabhai vte 0.11.16

nalin dahyabhai vte 0.11.9

nalin dahyabhai vte 0.11.8

nalin dahyabhai vte 0.11.1

nalin dahyabhai vte 0.11.0

nalin dahyabhai vte 0.10.21

nalin dahyabhai vte 0.10.20

nalin dahyabhai vte 0.10.12

nalin dahyabhai vte 0.10.11

nalin dahyabhai vte 0.10.4

nalin dahyabhai vte 0.10.3

nalin dahyabhai vte 0.25.1

nalin dahyabhai vte 0.24.3

nalin dahyabhai vte 0.22.5

nalin dahyabhai vte 0.30.0

nalin dahyabhai vte 0.29.1

nalin dahyabhai vte 0.27.4

nalin dahyabhai vte 0.27.3

nalin dahyabhai vte 0.25.90

nalin dahyabhai vte 0.24.2

nalin dahyabhai vte 0.23.3

nalin dahyabhai vte 0.22.4

nalin dahyabhai vte 0.21.5

nalin dahyabhai vte 0.21.4

nalin dahyabhai vte 0.20.0

nalin dahyabhai vte 0.19.4

nalin dahyabhai vte 0.16.14

nalin dahyabhai vte 0.15.0

nalin dahyabhai vte 0.16.10

nalin dahyabhai vte 0.16.9

nalin dahyabhai vte 0.16.1

nalin dahyabhai vte 0.16.0

nalin dahyabhai vte 0.14.1

nalin dahyabhai vte 0.14.0

nalin dahyabhai vte 0.13.1

nalin dahyabhai vte 0.13.0

nalin dahyabhai vte 0.11.15

nalin dahyabhai vte 0.11.14

nalin dahyabhai vte 0.11.7

nalin dahyabhai vte 0.11.6

nalin dahyabhai vte 0.10.29

nalin dahyabhai vte 0.10.28

nalin dahyabhai vte 0.10.27

nalin dahyabhai vte 0.10.19

nalin dahyabhai vte 0.10.17

nalin dahyabhai vte 0.10.10

nalin dahyabhai vte 0.10.9

nalin dahyabhai vte 0.10.2

nalin dahyabhai vte 0.10.1

nalin dahyabhai vte 0.10

Vendor Advisories

Debian Bug report logs - #677717 "malicious escape sequences can cause denial of service for vte-based terminals" Package: libvte9; Maintainer for libvte9 is Debian GNOME Maintainers <pkg-gnome-maintainers@listsaliothdebianorg>; Source for libvte9 is src:vte (PTS, buildd, popcon) Reported by: Timo Juhani Lindfors <timo ...

Exploits

source: wwwsecurityfocuscom/bid/54281/info VTE is prone to a vulnerability that may allow attackers to cause an affected application to consume excessive amounts of memory and CPU time, resulting in a denial-of-service condition echo -en "\e[2147483647L" echo -en "\e[2147483647M" echo -en "\e[2147483647P" ...