vendor:
xterm
by:
Kit Knox
7.5
CVSS
HIGH
Denial of Service (DoS)
400
CWE
Product Name: xterm
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: xterm (XFree86 3.3.3.1b(88b)), rxvt v2.6.1
2000
xterm Denial of Service Attack
If VT control-characters are displayed in the xterm, they can be interpreted and used to cause a denial of service attack against the client (and even the host running the client). This vulnerability allows remote users to crash the xterm of an admin or consume all available memory. The control characters can be injected into the xterm through various means such as rogue FTP servers, rogue banner messages on FTP, telnet, mud daemons, and spoofed syslog messages, web server logs, and FTP server logs.
Mitigation:
Unknown