CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:L/Au:S/C:N/I:N/A:P
AI Score
Confidence
Low
EPSS
Percentile
92.5%
The terminal dispatcher in mosh before 1.2.1 allows remote authenticated users to cause a denial of service (long loop and CPU consumption) via an escape sequence with a large repeat count value.
Vendor | Product | Version | CPE |
---|---|---|---|
keith_winstein | mosh | * | cpe:2.3:a:keith_winstein:mosh:*:*:*:*:*:*:*:* |
keith_winstein | mosh | 0.98c | cpe:2.3:a:keith_winstein:mosh:0.98c:*:*:*:*:*:*:* |
keith_winstein | mosh | 1.0 | cpe:2.3:a:keith_winstein:mosh:1.0:*:*:*:*:*:*:* |
keith_winstein | mosh | 1.1 | cpe:2.3:a:keith_winstein:mosh:1.1:*:*:*:*:*:*:* |
keith_winstein | mosh | 1.1.1 | cpe:2.3:a:keith_winstein:mosh:1.1.1:*:*:*:*:*:*:* |
keith_winstein | mosh | 1.1.2 | cpe:2.3:a:keith_winstein:mosh:1.1.2:*:*:*:*:*:*:* |
keith_winstein | mosh | 1.1.3 | cpe:2.3:a:keith_winstein:mosh:1.1.3:*:*:*:*:*:*:* |
keith_winstein | mosh | 1.1.3-1 | cpe:2.3:a:keith_winstein:mosh:1.1.3-1:*:*:*:*:*:*:* |
keith_winstein | mosh | 1.1.3-2 | cpe:2.3:a:keith_winstein:mosh:1.1.3-2:*:*:*:*:*:*:* |
keith_winstein | mosh | 1.2 | cpe:2.3:a:keith_winstein:mosh:1.2:*:*:*:*:*:*:* |
lists.fedoraproject.org/pipermail/package-announce/2012-June/082766.html
lists.fedoraproject.org/pipermail/package-announce/2012-June/082814.html
lists.fedoraproject.org/pipermail/package-announce/2012-June/082850.html
secunia.com/advisories/49260
www.openwall.com/lists/oss-security/2012/05/22/9
www.securityfocus.com/bid/53646
bugzilla.redhat.com/show_bug.cgi?id=823943
exchange.xforce.ibmcloud.com/vulnerabilities/75779
github.com/keithw/mosh/blob/master/ChangeLog
github.com/keithw/mosh/commit/9791768705528e911bfca6c4d8aa88139035060e
github.com/keithw/mosh/issues/271