← Vulnerability feed

Vulnerability record · CVE-2006-4573 · published 24 October 2006

CVE-2006-4573: Gnu screen vulnerability

Gnu · Screen

Multiple unspecified vulnerabilities in the "utf8 combining characters handling" (utf8_handle_comb function in encoding.c) in screen before 4.0.3 allows user-assisted attackers to cause a denial of service (crash or hang) via certain UTF8 sequences.

2.6 CVSS 2.0 Low EPSS 2.3% · top 17.5%
2.6CVSS 2.0 base score
2.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
42References
16 Jun 2026Last modified by NVD

Description

Multiple unspecified vulnerabilities in the "utf8 combining characters handling" (utf8_handle_comb function in encoding.c) in screen before 4.0.3 allows user-assisted attackers to cause a denial of service (crash or hang) via certain UTF8 sequences.

AV:N/AC:H/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://docs.info.apple.com/article.html?artnum=305530
http://lists.apple.com/archives/security-announce/2007/May/msg00004.html
http://lists.gnu.org/archive/html/screen-users/2006-10/msg00028.html Patch
http://secunia.com/advisories/22573
http://secunia.com/advisories/22583
http://secunia.com/advisories/22611
http://secunia.com/advisories/22647
http://secunia.com/advisories/22649
http://secunia.com/advisories/22707
http://secunia.com/advisories/22726
http://secunia.com/advisories/25402
http://security.gentoo.org/glsa/glsa-200611-01.xml
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.480775
http://www.debian.org/security/2006/dsa-1202
http://www.mandriva.com/security/advisories?name=MDKSA-2006:191
http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.026-screen.html
http://www.securityfocus.com/bid/20727
http://www.ubuntu.com/usn/usn-370-1
http://www.vupen.com/english/advisories/2006/4189
http://www.vupen.com/english/advisories/2007/1939
https://issues.rpath.com/browse/RPL-734
http://docs.info.apple.com/article.html?artnum=305530
http://lists.apple.com/archives/security-announce/2007/May/msg00004.html
http://lists.gnu.org/archive/html/screen-users/2006-10/msg00028.html Patch
http://secunia.com/advisories/22573
http://secunia.com/advisories/22583
http://secunia.com/advisories/22611
http://secunia.com/advisories/22647
http://secunia.com/advisories/22649
http://secunia.com/advisories/22707
http://secunia.com/advisories/22726
http://secunia.com/advisories/25402
http://security.gentoo.org/glsa/glsa-200611-01.xml
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.480775
http://www.debian.org/security/2006/dsa-1202
http://www.mandriva.com/security/advisories?name=MDKSA-2006:191
http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.026-screen.html
http://www.securityfocus.com/bid/20727
http://www.ubuntu.com/usn/usn-370-1
http://www.vupen.com/english/advisories/2006/4189

Track CVE-2006-4573 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2003-0972Gnu screen vulnerabilityInteger signedness error in ansi.c for GNU screen 4.0.1 and earlier, and 3.9.15 and earlier, allows local users to execute arbitrary code via a large…EPSS 3.4%9.8CVE-2021-26937Gnu screen argument injection vulnerabilityencoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly …EPSS 9.1%9.8CVE-2020-9366Gnu screen out-of-bounds write vulnerabilityA buffer overflow was found in the way GNU Screen before 4.8.0 treated the special escape OSC 49. Specially crafted output, or a special program, cou…EPSS 2.7%7.8CVE-2017-5618Gnu screen incorrect authorization vulnerabilityGNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile…EPSS 1.1%7.2CVE-2007-3048Gnu screen vulnerabilityGNU screen 4.0.3 allows local users to unlock the screen via a CTRL-C sequence at the password prompt. NOTE: multiple third parties report inability …EPSS 0.71%6.5CVE-2023-24626Gnu screen incorrect permission assignment vulnerabilitysocket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users t…EPSS 0.54%4.9CVE-2009-1214Gnu screen permissions and access controls vulnerabilityGNU screen 4.0.3 creates the /tmp/screen-exchange temporary file with world-readable permissions, which might allow local users to obtain sensitive s…EPSS 0.34%4.6CVE-2002-1602Gnu screen vulnerabilityBuffer overflow in the Braille module for GNU screen 3.9.11, when HAVE_BRAILLE is defined, allows local users to execute arbitrary code.EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2006-4573), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.