CVE-2005-3120
CRITICAL9.8EPSS 30.4%lynx - buffer overflow
Published: 10/17/2005Modified: 3/9/2026
Description
Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escape (ESC) characters.
Affected packages (4)
- Debian/lynxfrom 0, < 2.8.5-2sarge1
- Debian/lynxfrom 0, < 2.8.4.1b-3.3
- Debian/lynxfrom 0, < 2.8.4.1b-3.2
- Debian/lynx-curfrom 0, < 2.8.5-2.5woody1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |