CVE-2005-3120

See a problem?
Source
https://nvd.nist.gov/vuln/detail/CVE-2005-3120
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2005-3120.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2005-3120
Related
Published
2005-10-17T20:06:00Z
Modified
2024-06-30T12:01:22Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escape (ESC) characters.

References

Affected packages

Debian:11 / lynx

Package

Name
lynx
Purl
pkg:deb/debian/lynx?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.8.5-2sarge1

Ecosystem specific

{
    "urgency": "high"
}

Debian:12 / lynx

Package

Name
lynx
Purl
pkg:deb/debian/lynx?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.8.5-2sarge1

Ecosystem specific

{
    "urgency": "high"
}

Debian:13 / lynx

Package

Name
lynx
Purl
pkg:deb/debian/lynx?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.8.5-2sarge1

Ecosystem specific

{
    "urgency": "high"
}