Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-27135

Опубликовано: 10 фев. 2021
Источник: redhat
CVSS3: 9.6
EPSS Низкий

Описание

xterm before Patch #366 allows remote attackers to execute arbitrary code or cause a denial of service (segmentation fault) via a crafted UTF-8 combining character sequence.

A flaw was found in xterm. A specially crafted sequence of combining characters causes an out of bounds write leading to arbitrary code execution. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Меры по смягчению последствий

This vulnerability can be mitigated by disabling UTF-8 support in XTerm configuration. An entry such as "XTerm.vt100.utf8: false" in Xresources will disable UTF-8. This can be set as a system default in /etc/X11/Xresources, or per-user in ~/.Xresources. Note that this setting can still be overridden if xterm is invoked with the "-u8" command line option, so the mitigation may not protect all use cases.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6xtermOut of support scope
Red Hat Enterprise Linux 9xtermNot affected
Red Hat Enterprise Linux 7xtermFixedRHSA-2021:061722.02.2021
Red Hat Enterprise Linux 8xtermFixedRHSA-2021:061118.02.2021
Red Hat Enterprise Linux 8.1 Extended Update SupportxtermFixedRHSA-2021:065024.02.2021
Red Hat Enterprise Linux 8.2 Extended Update SupportxtermFixedRHSA-2021:065124.02.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1927559xterm: crash when processing combining characters

EPSS

Процентиль: 69%
0.00631
Низкий

9.6 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 4 лет назад

xterm before Patch #366 allows remote attackers to execute arbitrary code or cause a denial of service (segmentation fault) via a crafted UTF-8 combining character sequence.

CVSS3: 9.8
nvd
больше 4 лет назад

xterm before Patch #366 allows remote attackers to execute arbitrary code or cause a denial of service (segmentation fault) via a crafted UTF-8 combining character sequence.

CVSS3: 9.8
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 9.8
debian
больше 4 лет назад

xterm before Patch #366 allows remote attackers to execute arbitrary c ...

suse-cvrf
почти 4 года назад

Security update for xterm

EPSS

Процентиль: 69%
0.00631
Низкий

9.6 Critical

CVSS3