CVE-2005-3120 describes a critical stack-based buffer overflow in Lynx 2.8.6 and earlier, specifically within the HTrjis function, affecting Debian and Invisible Island Lynx distributions. This vulnerability allows remote NNTP servers to execute arbitrary code by sending crafted article headers containing Asian characters that trigger extra escape character additions. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog and lacking Metasploit/Nuclei modules, a Proof-of-Concept exploit (EDB-1256) exists, and it has garnered significant community discussion, indicating awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.8.6CPE matchmatch criteria | cpe:2.3:a:invisible-island:lynx:*:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:3.0:*:*:*:*:*:*:* | ||
3.1CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.