Multiple xterm clients contain a flaw that may allow a denial of service. The issue is triggered when a remote attacker is able to resize the terminal windows size by escape character sequences, which will cause a denial of service. This flaw will result in loss of availability for the xterm.
Classification
Location:
Remote/Network Access Required
Attack Type:
Denial of Service
Impact:
Loss of Availability
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
Solution
Upgrade to version PuTTY0.49 or higher, as it has been reported to fix this vulnerability. Michael Jennings has released a patch for Eterm. An upgrade is required as there are no known workarounds.