Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.57564
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-1202-1)
Summary:The remote host is missing an update for the Debian 'screen' package(s) announced via the DSA-1202-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'screen' package(s) announced via the DSA-1202-1 advisory.

Vulnerability Insight:
cstone and Rich Felker discovered that specially crafted UTF-8 sequences may lead an out of bands memory write when displayed inside the screen terminal multiplexer, allowing denial of service and potentially the execution of arbitrary code.

For the stable distribution (sarge) this problem has been fixed in version 4.0.2-4.1sarge1. Due to technical problems with the security buildd infrastructure this update lacks a build for the Sun Sparc architecture. It will be released as soon as the problems are resolved.

For the unstable distribution (sid) this problem has been fixed in version 4.0.3-0.1.

We recommend that you upgrade your screen package.

Affected Software/OS:
'screen' package(s) on Debian 3.1.

Solution:
Please install the updated package(s).

CVSS Score:
2.6

CVSS Vector:
AV:N/AC:H/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2006-4573
20727
http://www.securityfocus.com/bid/20727
22573
http://secunia.com/advisories/22573
22583
http://secunia.com/advisories/22583
22611
http://secunia.com/advisories/22611
22647
http://secunia.com/advisories/22647
22649
http://secunia.com/advisories/22649
22707
http://secunia.com/advisories/22707
22726
http://secunia.com/advisories/22726
25402
http://secunia.com/advisories/25402
ADV-2006-4189
http://www.vupen.com/english/advisories/2006/4189
ADV-2007-1939
http://www.vupen.com/english/advisories/2007/1939
APPLE-SA-2007-05-24
http://lists.apple.com/archives/security-announce/2007/May/msg00004.html
DSA-1202
http://www.debian.org/security/2006/dsa-1202
GLSA-200611-01
http://security.gentoo.org/glsa/glsa-200611-01.xml
MDKSA-2006:191
http://www.mandriva.com/security/advisories?name=MDKSA-2006:191
OpenPKG-SA-2006.026
http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.026-screen.html
SSA:2006-307-02
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.480775
USN-370-1
http://www.ubuntu.com/usn/usn-370-1
[screen-users] 20061023 Secfix release for screen: screen-4.0.3
http://lists.gnu.org/archive/html/screen-users/2006-10/msg00028.html
http://docs.info.apple.com/article.html?artnum=305530
https://issues.rpath.com/browse/RPL-734
CopyrightCopyright (C) 2008 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.