Vulnerability Name: | CVE-2012-2385 (CCN-75779) | ||||||||||||||||||||||||||||||||
Assigned: | 2012-05-22 | ||||||||||||||||||||||||||||||||
Published: | 2012-05-22 | ||||||||||||||||||||||||||||||||
Updated: | 2017-08-29 | ||||||||||||||||||||||||||||||||
Summary: | The terminal dispatcher in mosh before 1.2.1 allows remote authenticated users to cause a denial of service (long loop and CPU consumption) via an escape sequence with a large repeat count value. | ||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P) 3.5 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P/E:H/RL:OF/RC:C)
4.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:H/RL:OF/RC:C)
| ||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-399 | ||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2012-2385 Source: FEDORA Type: UNKNOWN FEDORA-2012-9422 Source: FEDORA Type: UNKNOWN FEDORA-2012-9414 Source: FEDORA Type: UNKNOWN FEDORA-2012-9442 Source: CCN Type: SA49260 Mosh Escape Sequence Denial of Service Vulnerability Source: SECUNIA Type: UNKNOWN 49260 Source: MLIST Type: UNKNOWN [oss-security] 20120522 Re: CVE Request -- mosh (and probably vte too): mosh server DoS (long loop) due improper parsing of terminal parameters in terminal dispatcher Source: CCN Type: OSVDB ID: 82082 Mosh mosh-server Command Parsing Endless Loop Remote DoS Source: BID Type: UNKNOWN 53646 Source: CCN Type: BID-53646 Mosh Remote Denial of Service Vulnerability Source: MISC Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=823943 Source: XF Type: UNKNOWN mosh-sequences-dos(75779) Source: XF Type: UNKNOWN mosh-sequences-dos(75779) Source: CONFIRM Type: UNKNOWN https://github.com/keithw/mosh/blob/master/ChangeLog Source: CONFIRM Type: Patch https://github.com/keithw/mosh/commit/9791768705528e911bfca6c4d8aa88139035060e Source: CCN Type: Mosh GIT Repository malicious escape sequences can cause denial of service for mosh-server Source: CONFIRM Type: UNKNOWN https://github.com/keithw/mosh/issues/271 | ||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||
BACK |