First published: Thu Jun 01 2000(Updated: )
xterm, Eterm, and rxvt allow an attacker to cause a denial of service by embedding certain escape characters which force the window to be resized.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
rxvt | =2.6.1 | |
XFree86 X Server | =4.0 | |
XFree86 X Server | =3.3.3 | |
PuTTY | =0.48 | |
Eterm | =0.8.10 | |
=0.8.10 | ||
=0.48 | ||
=2.6.1 | ||
=3.3.3 | ||
=4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0476 is classified as a denial of service vulnerability.
To mitigate CVE-2000-0476, users should update affected software to the latest versions that address this vulnerability.
CVE-2000-0476 affects rxvt 2.6.1, XFree86 X Server versions 3.3.3 and 4.0, Eterm 0.8.10, and PuTTY 0.48.
Yes, CVE-2000-0476 can be exploited remotely if an attacker sends malicious escape characters to an affected terminal.
The potential consequence of CVE-2000-0476 is that it can cause a denial of service, disrupting the normal operation of the terminal emulator.