CVE-2005-3120

Publication date 17 October 2005

Last updated 17 July 2025


Ubuntu priority

Cvss 3 Severity Score

9.8 · Critical

Score breakdown

Description

Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escape (ESC) characters.

Status

Package Ubuntu Release Status
lynx 7.04 feisty
Fixed 2.8.5-2ubuntu1
6.10 edgy
Fixed 2.8.5-2ubuntu1
6.06 LTS dapper
Fixed 2.8.5-2ubuntu1
lynx-cur 7.04 feisty
Fixed 2.8.6-18
6.10 edgy
Fixed 2.8.6-18
6.06 LTS dapper
Fixed 2.8.6-18

Severity score breakdown

CVSS version: CVSS v3.0

Base score 9.8 · Critical

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Related Ubuntu Security Notices (USN)

    • USN-206-1
    • Lynx vulnerability
    • 17 October 2005

Other references


Access our resources on patching vulnerabilities