CVE-2005-3120

CRITICAL9.8EPSS 30.4%

lynx - buffer overflow

Published: 10/17/2005Modified: 3/9/2026
Also known as:DSA-874-1DEBIAN-CVE-2005-3120

Description

Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escape (ESC) characters.

Affected packages (4)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (1)