CVE-2015-6806
GNU Screen < 4.3.1 - Denial of Service via Escape Sequence with Large Repeat Count
Title source: llmDescription
The MScrollV function in ansi.c in GNU screen 4.3.1 and earlier does not properly limit recursion, which allows remote attackers to cause a denial of service (stack consumption) via an escape sequence with a large repeat count value.
References (8)
Core 8
Core References
Exploit mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/09/03/11
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/09/01/1
Patch x_refsource_confirm
http://git.savannah.gnu.org/cgit/screen.git/commit/?id=b7484c224738247b510ed0d268cd577076958f1b
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/09/03/4
Exploit, Vendor Advisory x_refsource_confirm
https://savannah.gnu.org/bugs/?45713
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2015/dsa-3352
Vendor Advisory vendor-advisory
x_refsource_ubuntu
https://usn.ubuntu.com/3996-1/
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00001.html
Scores
EPSS
0.0064
EPSS Percentile
70.9%
Details
CWE
CWE-119
Status
published
Products (1)
gnu/gnu_screen
< 4.3.1
Published
Sep 28, 2015
Tracked Since
Feb 18, 2026