PublicDateAtUSN: 2015-09-28 Candidate: CVE-2015-6806 PublicDate: 2015-09-28 20:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6806 http://www.openwall.com/lists/oss-security/2015/09/01/1 https://ubuntu.com/security/notices/USN-3996-1 Description: The MScrollV function in ansi.c in GNU screen 4.3.1 and earlier does not properly limit recursion, which allows remote attackers to cause a denial of service (stack consumption) via an escape sequence with a large repeat count value. Ubuntu-Description: It was discovered that GNU screen mishandled certain crafted input. An attacker could use this vulnerability to cause a denial of service. Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=797624 https://savannah.gnu.org/bugs/?45713 Priority: low Discovered-by: Assigned-to: CVSS: Patches_screen: upstream: http://git.savannah.gnu.org/cgit/screen.git/commit/?id=c336a32a1dcd445e6b83827f83531d4c6414e2cd upstream_screen: released (4.3.1-2) precise_screen: ignored (reached end-of-life) precise/esm_screen: released (4.0.3-14ubuntu8.1) trusty_screen: ignored (reached end-of-life) trusty/esm_screen: released (4.1.0~20120320gitdb59704-9ubuntu0.1~esm1) vivid_screen: ignored (reached end-of-life) vivid/stable-phone-overlay_screen: DNE vivid/ubuntu-core_screen: DNE wily_screen: not-affected (4.3.1-2) xenial_screen: not-affected (4.3.1-2) esm-infra/xenial_screen: not-affected (4.3.1-2) yakkety_screen: not-affected (4.3.1-2) zesty_screen: not-affected (4.3.1-2) artful_screen: not-affected (4.3.1-2) bionic_screen: not-affected (4.3.1-2) cosmic_screen: not-affected (4.3.1-2) disco_screen: not-affected (4.3.1-2) devel_screen: not-affected (4.3.1-2)