OpenPKG Security Advisory
OpenPKG-SA-2006.026
Publisher Name: OpenPKG GmbH
Publisher Home: http://openpkg.com/
Advisory Id (public): OpenPKG-SA-2006.026
Advisory Type: OpenPKG Security Advisory (SA)
Advisory Directory: http://openpkg.com/go/OpenPKG-SA
Advisory Document: http://openpkg.com/go/OpenPKG-SA-2006.026
Advisory Published: 2010-09-03 23:40 UTC
Issue Id (internal): OpenPKG-SI-20061026.01
Issue First Created: 2006-10-26
Issue Last Modified: 2006-12-07
Issue Revision: 08
Subject Name: Screen
Subject Summary: Virtual Screen Manager
Subject Home: http://www.gnu.org/software/screen/
Subject Versions: * <= 4.0.2
Vulnerability Id: CVE-2006-4573
Vulnerability Scope: global (not OpenPKG specific)
Attack Feasibility: run-time
Attack Vector: local system
Attack Impact: denial of service
Description:
According to a vendor release announcement [0], a denial of service
vulnerability exists in the virtual terminal application GNU screen
[1], version 4.0.2 and earlier. The vulnerabilities exist in the
handling of "UTF-8 combining characters" and allow user-assisted
attackers to cause a Denial of Service (crash or hang of GNU screen)
via certain UTF-8 character sequences.
References:
[0] http://lists.gnu.org/archive/html/screen-users/2006-10/msg00028.html
[1] http://www.gnu.org/software/screen/
Primary Package Name: screen
Primary Package Home: http://openpkg.org/go/package/screen
Affected Distribution: Affected Branch: Affected Package:
OpenPKG Enterprise E1.0-SOLID n/a
OpenPKG Community 2-STABLE-20061018 screen-4.0.2-2.20061018
OpenPKG Community 2-STABLE screen-4.0.2-2.20061018
OpenPKG Community CURRENT screen-4.0.2-20061013
Corrected Distribution: Corrected Branch: Corrected Package:
OpenPKG Enterprise E1.0-SOLID screen-4.0.3-E1.0.0
OpenPKG Community 2-STABLE-20061018 screen-4.0.3-2.20061023
OpenPKG Community 2-STABLE screen-4.0.3-2.20061023
OpenPKG Community CURRENT screen-4.0.3-20061023