CVE-2005-3120 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 23.3% (pctl 98)
Patch early
A public exploit exists.
Description
Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escape (ESC) characters.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 23.26% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-131 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-10-17 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| debian | debian linux |
| invisible-island | lynx |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Lynx 2.8.6dev.13 - Remote Buffer Overflow (PoC) | 2005-10-17 |
References
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.7/SCOSA-2006.7.txt
- ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.47/SCOSA-2005.47.txt
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-October/038019.html
- http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.html
- http://secunia.com/advisories/17150
- http://secunia.com/advisories/17216
- http://secunia.com/advisories/17230
- http://secunia.com/advisories/17231
- http://secunia.com/advisories/17238
- http://secunia.com/advisories/17248
- http://secunia.com/advisories/17340
- http://secunia.com/advisories/17360
- http://secunia.com/advisories/17444
- http://secunia.com/advisories/17445
- http://secunia.com/advisories/17480
- http://secunia.com/advisories/18376
- http://secunia.com/advisories/18584
- http://secunia.com/advisories/20383
- http://securitytracker.com/id?1015065
- http://slackware.com/security/viewer.php?l=slackware-security&y=2005&m=slackware-security.423056
→ the Explorer · watch your stack · NVD