CVE-2006-4573
published 2006-10-24CVE-2006-4573: Multiple unspecified vulnerabilities in the "utf8 combining characters handling" (utf8_handle_comb function in encoding.c) in screen before 4.0.3 allows…
PriorityP47low2.6CVSS 2.0
AVNACHAuNCNINAP
EPSS
2.11%
79.7th percentile
Multiple unspecified vulnerabilities in the "utf8 combining characters handling" (utf8_handle_comb function in encoding.c) in screen before 4.0.3 allows user-assisted attackers to cause a denial of service (crash or hang) via certain UTF8 sequences.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | screen | < screen 4.0.3-0.1 (bookworm) | screen 4.0.3-0.1 (bookworm) |
| gnu | screen | <= 4.0.2 | — |
| gnu | screen | >= 0 < 4.0.3-0.1 | 4.0.3-0.1 |
| gnu | screen | >= 0 < 4.0.3-0.1 | 4.0.3-0.1 |
| gnu | screen | >= 0 < 4.0.3-0.1 | 4.0.3-0.1 |
| gnu | screen | >= 0 < 4.0.3-0.1 | 4.0.3-0.1 |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
osv2.6LOW
vendor_debian2.6MEDIUM
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5v6p-jx73-rq6x: Multiple unspecified vulnerabilities in the "utf8 combining characters handling" (utf8_handle_comb function in encoding
ghsa_unreviewed·2022-05-01
CVE-2006-4573 [LOW] GHSA-5v6p-jx73-rq6x: Multiple unspecified vulnerabilities in the "utf8 combining characters handling" (utf8_handle_comb function in encoding
Multiple unspecified vulnerabilities in the "utf8 combining characters handling" (utf8_handle_comb function in encoding.c) in screen before 4.0.3 allows user-assisted attackers to cause a denial of service (crash or hang) via certain UTF8 sequences.
OSV
CVE-2006-4573: Multiple unspecified vulnerabilities in the "utf8 combining characters handling" (utf8_handle_comb function in encoding
osv·2006-10-24·CVSS 2.6
CVE-2006-4573 [LOW] CVE-2006-4573: Multiple unspecified vulnerabilities in the "utf8 combining characters handling" (utf8_handle_comb function in encoding
Multiple unspecified vulnerabilities in the "utf8 combining characters handling" (utf8_handle_comb function in encoding.c) in screen before 4.0.3 allows user-assisted attackers to cause a denial of service (crash or hang) via certain UTF8 sequences.
Ubuntu
screen vulnerability
vendor_ubuntu·2006-11-01
CVE-2006-4573 screen vulnerability
Title: screen vulnerability
Summary: screen vulnerability
cstone and Rich Felker discovered a programming error in the UTF8 string
handling code of "screen" leading to a denial of service. If a crafted
string was displayed within a screen session, screen would crash or
possibly execute arbitrary code.
Instructions: After a standard system upgrade you need to restart any running screen
sessions to effect the necessary changes.
Red Hat
screen buffer overflow
vendor_redhat·2006-10-23·CVSS 2.6
CVE-2006-4573 [LOW] screen buffer overflow
screen buffer overflow
Multiple unspecified vulnerabilities in the "utf8 combining characters handling" (utf8_handle_comb function in encoding.c) in screen before 4.0.3 allows user-assisted attackers to cause a denial of service (crash or hang) via certain UTF8 sequences.
Statement: Red Hat no longer plans to fix this issue in Red Hat Enterprise Linux 4.
Package: screen (Red Hat Enterprise Linux 4) - Will not fix
Package: screen (Red Hat Enterprise Linux 5) - Not affected
Package: screen (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2006-4573: screen - Multiple unspecified vulnerabilities in the "utf8 combining characters handling"...
vendor_debian·2006·CVSS 2.6
CVE-2006-4573 [LOW] CVE-2006-4573: screen - Multiple unspecified vulnerabilities in the "utf8 combining characters handling"...
Multiple unspecified vulnerabilities in the "utf8 combining characters handling" (utf8_handle_comb function in encoding.c) in screen before 4.0.3 allows user-assisted attackers to cause a denial of service (crash or hang) via certain UTF8 sequences.
Scope: local
bookworm: resolved (fixed in 4.0.3-0.1)
bullseye: resolved (fixed in 4.0.3-0.1)
forky: resolved (fixed in 4.0.3-0.1)
sid: resolved (fixed in 4.0.3-0.1)
trixie: resolved (fixed in 4.0.3-0.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-4573 screen buffer overflow
bugzilla·2006-10-24·CVSS 2.6
CVE-2006-4573 [LOW] CVE-2006-4573 screen buffer overflow
CVE-2006-4573 screen buffer overflow
From the screen-users mailing list:
I've just released screen-4.0.3. This is not the promised next version
with vertical split and other cool things, but just a security release
that fixes two bugs in the utf8 combining characters handling. The
bugs could be used to crash/hang screen by writing a special string
to a window.
The fixed version is (as usual) available via:
ftp://ftp.uni-erlangen.de/pub/utilities/screen/screen-4.0.3.tar.gz
Credits go to cstone & Rich Felker for finding the bugs.
Kees Cook of Ubuntu analysed this issue and determined that it's likely an
exploitable issue, but it's non trivial to exploit. This will require a fair
amount of user interaction to exploit, thus the low severity.
This issue also likely affects RHEL2.1 and RH
Bugzilla
CVE-2006-4573 screen buffer overflow
bugzilla·2006-10-24·CVSS 2.6
CVE-2006-4573 [LOW] CVE-2006-4573 screen buffer overflow
CVE-2006-4573 screen buffer overflow
+++ This bug was initially created as a clone of Bug #212056 +++
From the screen-users mailing list:
I've just released screen-4.0.3. This is not the promised next version
with vertical split and other cool things, but just a security release
that fixes two bugs in the utf8 combining characters handling. The
bugs could be used to crash/hang screen by writing a special string
to a window.
The fixed version is (as usual) available via:
ftp://ftp.uni-erlangen.de/pub/utilities/screen/screen-4.0.3.tar.gz
Credits go to cstone & Rich Felker for finding the bugs.
Kees Cook of Ubuntu analysed this issue and determined that it's likely an
exploitable issue, but it's non trivial to exploit. This will require a fair
amount of user interaction to exploit, thu
http://docs.info.apple.com/article.html?artnum=305530http://lists.apple.com/archives/security-announce/2007/May/msg00004.htmlhttp://lists.gnu.org/archive/html/screen-users/2006-10/msg00028.htmlhttp://secunia.com/advisories/22573http://secunia.com/advisories/22583http://secunia.com/advisories/22611http://secunia.com/advisories/22647http://secunia.com/advisories/22649http://secunia.com/advisories/22707http://secunia.com/advisories/22726http://secunia.com/advisories/25402http://security.gentoo.org/glsa/glsa-200611-01.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.480775http://www.debian.org/security/2006/dsa-1202http://www.mandriva.com/security/advisories?name=MDKSA-2006:191http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.026-screen.htmlhttp://www.securityfocus.com/bid/20727http://www.ubuntu.com/usn/usn-370-1http://www.vupen.com/english/advisories/2006/4189http://www.vupen.com/english/advisories/2007/1939https://issues.rpath.com/browse/RPL-734http://docs.info.apple.com/article.html?artnum=305530http://lists.apple.com/archives/security-announce/2007/May/msg00004.htmlhttp://lists.gnu.org/archive/html/screen-users/2006-10/msg00028.htmlhttp://secunia.com/advisories/22573http://secunia.com/advisories/22583http://secunia.com/advisories/22611http://secunia.com/advisories/22647http://secunia.com/advisories/22649http://secunia.com/advisories/22707http://secunia.com/advisories/22726http://secunia.com/advisories/25402http://security.gentoo.org/glsa/glsa-200611-01.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.480775http://www.debian.org/security/2006/dsa-1202http://www.mandriva.com/security/advisories?name=MDKSA-2006:191http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.026-screen.htmlhttp://www.securityfocus.com/bid/20727http://www.ubuntu.com/usn/usn-370-1http://www.vupen.com/english/advisories/2006/4189http://www.vupen.com/english/advisories/2007/1939https://issues.rpath.com/browse/RPL-734
2006-10-24
Published