Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-27135

Опубликовано: 10 фев. 2021
Источник: redhat
CVSS3: 9.6

Описание

xterm before Patch #366 allows remote attackers to execute arbitrary code or cause a denial of service (segmentation fault) via a crafted UTF-8 combining character sequence.

A flaw was found in xterm. A specially crafted sequence of combining characters causes an out of bounds write leading to arbitrary code execution. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Меры по смягчению последствий

This vulnerability can be mitigated by disabling UTF-8 support in XTerm configuration. An entry such as "XTerm.vt100.utf8: false" in Xresources will disable UTF-8. This can be set as a system default in /etc/X11/Xresources, or per-user in ~/.Xresources. Note that this setting can still be overridden if xterm is invoked with the "-u8" command line option, so the mitigation may not protect all use cases.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6xtermOut of support scope
Red Hat Enterprise Linux 9xtermNot affected
Red Hat Enterprise Linux 7xtermFixedRHSA-2021:061722.02.2021
Red Hat Enterprise Linux 8xtermFixedRHSA-2021:061118.02.2021
Red Hat Enterprise Linux 8.1 Extended Update SupportxtermFixedRHSA-2021:065024.02.2021
Red Hat Enterprise Linux 8.2 Extended Update SupportxtermFixedRHSA-2021:065124.02.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1927559xterm: crash when processing combining characters

9.6 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 5 лет назад

xterm before Patch #366 allows remote attackers to execute arbitrary code or cause a denial of service (segmentation fault) via a crafted UTF-8 combining character sequence.

CVSS3: 9.8
nvd
почти 5 лет назад

xterm before Patch #366 allows remote attackers to execute arbitrary code or cause a denial of service (segmentation fault) via a crafted UTF-8 combining character sequence.

CVSS3: 9.8
msrc
почти 4 года назад

Описание отсутствует

CVSS3: 9.8
debian
почти 5 лет назад

xterm before Patch #366 allows remote attackers to execute arbitrary c ...

suse-cvrf
больше 4 лет назад

Security update for xterm

9.6 Critical

CVSS3