PT-2021-3613 · Unknown+7 · Gnu Screen+7

Tavis Ormandy

·

Published

2021-02-09

·

Updated

2024-06-15

·

CVE-2021-26937

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GNU Screen versions through 4.8.0
Description The issue is related to incorrect handling of UTF-8 character sequences in the encoding.c component of GNU Screen. This can be exploited by a remote attacker to gain access to confidential data, compromise data integrity, and cause a denial of service, potentially leading to an application crash.
Recommendations For GNU Screen versions through 4.8.0, update to a version later than 4.8.0 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3263
ALT-PU-2021-3266
ALT-PU-2021-3614
AZL-7356
BDU:2021-03746
CESA-2021_0742
CVE-2021-26937
DLA-2570-1
DSA-4861-1
MGASA-2021-0109
OESA-2021-1090
OPENSUSE-SU-2021:0304-1
OPENSUSE-SU-2021_0304-1
OPENSUSE-SU-2024:11884-1
RHSA-2021:0742
RHSA-2021_0742
RHSA-2022:1074
SUSE-SU-2021:0491-1
SUSE-SU-2021:0492-1
SUSE-SU-2021_0491-1
SUSE-SU-2021_0492-1
USN-4747-1
USN-4747-2

Affected Products

Alt Linux
Astra Linux
Centos
Gnu Screen
Linuxmint
Red Hat
Suse
Ubuntu