Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-26937

Опубликовано: 10 фев. 2021
Источник: redhat
CVSS3: 9.6

Описание

encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence.

A flaw was found in screen. A specially crafted sequence of combining characters could cause an out of bounds write leading to arbitrary code execution. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Меры по смягчению последствий

This flaw is in utf8 processing; if your screen configuration does not enable utf8 (through configuration such as "defencoding utf-8" in .screenrc), you are not vulnerable.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6screenOut of support scope
Red Hat Enterprise Linux 7screenFixedRHSA-2021:074208.03.2021
Red Hat Enterprise Linux 7.7 Advanced Update SupportscreenFixedRHSA-2022:107428.03.2022
Red Hat Enterprise Linux 7.7 Telco Extended Update SupportscreenFixedRHSA-2022:107428.03.2022
Red Hat Enterprise Linux 7.7 Update Services for SAP SolutionsscreenFixedRHSA-2022:107428.03.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1927062screen: crash when processing combining chars

9.6 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 5 лет назад

encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence.

CVSS3: 9.8
nvd
почти 5 лет назад

encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence.

CVSS3: 9.8
msrc
около 4 лет назад

encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence.

CVSS3: 9.8
debian
почти 5 лет назад

encoding.c in GNU Screen through 4.8.0 allows remote attackers to caus ...

suse-cvrf
почти 5 лет назад

Security update for screen

9.6 Critical

CVSS3