Back to search
CVE-2003-0972
Published: Dec 2, 2003
Modified: Aug 8, 2024
PUBLISHED
Description
Integer signedness error in ansi.c for GNU screen 4.0.1 and earlier, and 3.9.15 and earlier, allows local users to execute arbitrary code via a large number of ";" (semicolon) characters in escape sequences, which leads to a buffer overflow.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
10539
third-party-advisory
x_refsource_SECUNIA
20031127 GNU screen buffer overflow
mailing-list
x_refsource_BUGTRAQ
DSA-408
vendor-advisory
x_refsource_DEBIAN
CLA-2004:809
vendor-advisory
x_refsource_CONECTIVA
MDKSA-2003:113
vendor-advisory
x_refsource_MANDRAKE
http://groups.yahoo.com/group/gnu-screen/message/3118
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now