Junglewise Threat Intelligence

CVE-1999-0251: Unix talk denial of service via display disruption

CVE-1999-0251 · Severity: medium · CVSS 5 · Published 1997-01-01

Executive brief

A vulnerability in the 'talk' communication program allows remote individuals to disrupt a user's terminal display. This can interfere with active work sessions and cause a minor denial of service by making the screen unreadable. While it does not expose sensitive data, it can impact employee productivity and system usability.

Technical details

A denial of service vulnerability exists in the Unix 'talk' utility. The flaw allows a remote, unauthenticated attacker to send malformed or unexpected data that disrupts the victim's terminal display. This is likely achieved by sending escape sequences or control characters that the talk daemon or client fails to sanitize before rendering. The primary impact is the loss of availability of the user's current terminal session. No authentication is required to trigger the condition over the network.

Affected products

  • Unix talk

Timeline

  • 1997-01-01: disclosed

References