CVE-2003-0071: Low severity Xfree86 Project X11r6 vulnerability
Published Mar 3, 2003
·Updated
The DEC UDK processing feature in the xterm terminal emulator in XFree86 4.2.99.4 and earlier allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.
Affected Software
6 affected components
Xfree86 Project X11r6=4.1.0
Xfree86 Project X11r6=4.0.3
Xfree86 Project X11r6=4.2.1
Xfree86 Project X11r6=4.0
Xfree86 Project X11r6=4.0.1
Xfree86 Project X11r6=4.2.0
Event History
Mar 3, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-0071?
CVE-2003-0071 is classified as a denial of service vulnerability.
2
How does CVE-2003-0071 affect XFree86?
CVE-2003-0071 allows attackers to cause a denial of service by sending a specific character escape sequence to xterm.
3
How do I fix CVE-2003-0071?
To mitigate CVE-2003-0071, upgrade to a patched version of XFree86 that is not vulnerable.
4
Which versions of XFree86 are affected by CVE-2003-0071?
CVE-2003-0071 affects XFree86 versions 4.2.99.4 and earlier, including versions 4.1.0, 4.0.3, and 4.2.1.
5
Is there a workaround for CVE-2003-0071?
A potential workaround for CVE-2003-0071 is to avoid using xterm if upgrading is not an option.