SB2017061434 - Buffer overflow in vte (Alpine package)
Published: June 14, 2017
Security Bulletin ID
SB2017061434
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2012-2738)
The vulnerability allows a remote #AU# to perform service disruption.
The VteTerminal in gnome-terminal (vte) before 0.32.2 allows remote authenticated users to cause a denial of service (long loop and CPU consumption) via an escape sequence with a large repeat count value.
Remediation
Install update from vendor's website.