Rxvt 2.7.10 is vulnerable to a denial of service attack by passing the value -2^31 inside a terminal escape code, which results in a non-invertible integer that eventually leads to a segfault due to an out of bounds read.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2017/05/01/15 | Exploit Mailing List Patch Third Party Advisory |
http://www.openwall.com/lists/oss-security/2017/05/01/18 | Mailing List Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2021/06/msg00012.html | Mailing List Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2017-05-02T14:00:00
Updated: 2021-06-09T14:06:17
Reserved: 2017-04-05T00:00:00
Link: CVE-2017-7483
JSON object: View
NVD Information
Status : Analyzed
Published: 2017-05-02T14:59:00.660
Modified: 2023-02-01T17:40:22.627
Link: CVE-2017-7483
JSON object: View
Redhat Information
No data.
CWE