LWN.net Logo

mosh: denial of service

Package(s):mosh CVE #(s):CVE-2012-2385
Created:June 26, 2012 Updated:April 10, 2013
Description: From the Red Hat bugzilla:

A denial of service flaw was found in the way mosh, a remote terminal application, performed processing of parameters that have been passed to the terminal in the terminal dispatcher class (previously there was no limit for the count of parameters, which were allowed to be passed to the dispatcher). A remote attacker could use this flaw to cause a denial of service (mosh server to enter long for loop when trying to process the parameters) via specially-crafted escape sequence string.

Alerts:
Fedora FEDORA-2012-9442 2012-06-26
Fedora FEDORA-2012-9414 2012-06-26
Fedora FEDORA-2012-9422 2012-06-26
Mageia MGASA-2012-0182 2012-07-29
Mandriva MDVSA-2013:104 2013-04-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds