CVE-2016-20042: Trn Threaded Usenet News Reader

High severity, CVSS 8.4. EPSS: 0.1% chance of exploitation in the next 30 days.

TRN 3.6-23 contains a stack buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized argument to the application. Attackers can craft a malicious command-line argument with 156 bytes of padding followed by a return address to overwrite the instruction pointer and execute shellcode with user privileges.

Affected products

  • Trn Threaded Usenet News Reader: version 3.6-23 only

Published 2026-03-28. Last modified 2026-06-17.