CVE-2016-20042 identifies a stack buffer overflow vulnerability in TRN version 3.6-23, enabling local attackers to execute arbitrary code. This is achieved by supplying an oversized command-line argument, which overwrites the instruction pointer and allows shellcode execution with user privileges. With a CVSS v3.1 score of 8.4 (High), the vulnerability presents a local attack vector with low complexity, requiring no privileges or user interaction, and poses high impacts to confidentiality, integrity, and availability. There is currently no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. Furthermore, the vulnerability has garnered minimal community attention, with no mentions in discussions or media coverage, and is not present on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Trn | Threaded USENET News Reader | 3.6-23CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.