CVE-2017-7483: Integer Overflow
Published May 2, 2017
·Updated
Rxvt 2.7.10 is vulnerable to a denial of service attack by passing the value -2^31 inside a terminal escape code, which results in a non-invertible integer that eventually leads to a segfault due to an out of bounds read.
Affected Software
2 affected components
Rxvt Project Rxvt
Debian Debian Linux=9.0
Remediation
Patch Available
Event History
May 2, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-7483?
CVE-2017-7483 is classified as a denial of service vulnerability.
2
How does CVE-2017-7483 exploit occur?
CVE-2017-7483 exploits occur by passing the value -2^31 into a terminal escape code, leading to a segmentation fault.
3
Which software versions are affected by CVE-2017-7483?
CVE-2017-7483 affects Rxvt version 2.7.10 and Debian Linux 9.0.
4
How do I fix CVE-2017-7483?
To fix CVE-2017-7483, update to a patched version of Rxvt that resolves the denial of service vulnerability.
5
Is CVE-2017-7483 being actively exploited?
As of the last update, there were no known active exploits specifically leveraging CVE-2017-7483.