CVE-2015-6806

GNU Screen < 4.3.1 - Denial of Service via Escape Sequence with Large Repeat Count

Title source: llm
STIX 2.1

Description

The MScrollV function in ansi.c in GNU screen 4.3.1 and earlier does not properly limit recursion, which allows remote attackers to cause a denial of service (stack consumption) via an escape sequence with a large repeat count value.

References (8)

Core 8
Core References
Exploit mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/09/03/11
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/09/01/1
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/09/03/4
Exploit, Vendor Advisory x_refsource_confirm
https://savannah.gnu.org/bugs/?45713
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2015/dsa-3352
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3996-1/

Scores

EPSS 0.0064
EPSS Percentile 70.9%

Details

CWE
CWE-119
Status published
Products (1)
gnu/gnu_screen < 4.3.1
Published Sep 28, 2015
Tracked Since Feb 18, 2026