CVE-2005-3120
Last modified
CVE-2005-3120 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escape (ESC) characters.. EPSS estimates a 23.26% chance of exploitation in the next 30 days.
Description
Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escape (ESC) characters.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Invisible-Island | Lynx | <= 2.8.6 |
| Debian | Debian Linux | 3.0 |
| Debian | Debian Linux | 3.1 |
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-October/038019.htmlBroken Link, Patch, Vendor Advisory
- http://secunia.com/advisories/17150Broken Link
- http://secunia.com/advisories/17216Broken Link
- http://secunia.com/advisories/17230Broken Link
- http://secunia.com/advisories/17231Broken Link
- http://secunia.com/advisories/17238Broken Link
- http://secunia.com/advisories/17248Broken Link
- http://secunia.com/advisories/17340Broken Link
- http://secunia.com/advisories/17360Broken Link
- http://secunia.com/advisories/17444Broken Link
- http://secunia.com/advisories/17445Broken Link
- http://secunia.com/advisories/17480Broken Link
- http://secunia.com/advisories/18376Broken Link
- http://secunia.com/advisories/18584Broken Link
- http://secunia.com/advisories/20383Broken Link
- http://securitytracker.com/id?1015065Broken Link, Third Party Advisory, VDB Entry
- http://support.avaya.com/elmodocs2/security/ASA-2006-010.htmThird Party Advisory
- http://www.debian.org/security/2005/dsa-874Mailing List, Third Party Advisory
- http://www.debian.org/security/2005/dsa-876Mailing List, Third Party Advisory
- http://www.debian.org/security/2006/dsa-1085Mailing List, Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200510-15.xmlThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:186Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2005-803.htmlBroken Link, Vendor Advisory
- http://www.securityfocus.com/archive/1/419763/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/435689/30/4740/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/15117Broken Link, Third Party Advisory, VDB Entry
- https://usn.ubuntu.com/206-1/Broken Link
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-October/038019.htmlBroken Link, Patch, Vendor Advisory
- http://secunia.com/advisories/17150Broken Link
- http://secunia.com/advisories/17216Broken Link
- http://secunia.com/advisories/17230Broken Link
- http://secunia.com/advisories/17231Broken Link
- http://secunia.com/advisories/17238Broken Link
- http://secunia.com/advisories/17248Broken Link
- http://secunia.com/advisories/17340Broken Link
- http://secunia.com/advisories/17360Broken Link
- http://secunia.com/advisories/17444Broken Link
- http://secunia.com/advisories/17445Broken Link
- http://secunia.com/advisories/17480Broken Link
- http://secunia.com/advisories/18376Broken Link
- http://secunia.com/advisories/18584Broken Link
- http://secunia.com/advisories/20383Broken Link
- http://securitytracker.com/id?1015065Broken Link, Third Party Advisory, VDB Entry
- http://support.avaya.com/elmodocs2/security/ASA-2006-010.htmThird Party Advisory
- http://www.debian.org/security/2005/dsa-874Mailing List, Third Party Advisory
- http://www.debian.org/security/2005/dsa-876Mailing List, Third Party Advisory
- http://www.debian.org/security/2006/dsa-1085Mailing List, Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200510-15.xmlThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:186Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2005-803.htmlBroken Link, Vendor Advisory
- http://www.securityfocus.com/archive/1/419763/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/435689/30/4740/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/15117Broken Link, Third Party Advisory, VDB Entry
- https://usn.ubuntu.com/206-1/Broken Link
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-3120?
How severe is CVE-2005-3120?
How do I fix CVE-2005-3120?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-3114Buffer overflow in the ActiveX control for NateOn Messenger …
- CVE-2005-3115mpeg-tools before 1.5b-r2 creates multiple temporary files i…
- CVE-2005-3116Stack-based buffer overflow in a shared library as used by t…
- CVE-2005-3117Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2005-3118Mason before 1.0.0 does not install the init script after th…
- CVE-2005-3119Memory leak in the request_key_auth_destroy function in requ…
- CVE-2005-3121A rule file in module-assistant before 0.9.10 causes a tempo…
- CVE-2005-3122Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2005-3123Directory traversal vulnerability in GNUMP3D before 2.9.6 al…
- CVE-2005-3124syslogtocern in Acme thttpd before 2.23 allows local users t…
- CVE-2005-3125Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2005-3126The (1) kantiword (kantiword.sh) and (2) gantiword (gantiwor…
Are you affected by CVE-2005-3120?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
