PT-2021-6514 · Tcl+3 · Tcl+3

Salmonx

·

Published

2021-05-07

·

Updated

2025-08-12

·

CVE-2021-35331

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tcl version 8.6.11
Description A format string vulnerability in the nmakehlp.c component of the Tcl programming language may allow code execution via a crafted file. This issue is related to insufficient processing of format strings, which could enable a remote attacker to access confidential data, compromise its integrity, and cause a denial of service using a specially crafted file. Note that multiple third parties dispute the significance of this finding.
Recommendations For Tcl version 8.6.11, as a temporary workaround, consider restricting access to the nmakehlp.c component until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Externally-Controlled Format String

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3242
ALT-PU-2024-9046
BDU:2022-01774
CVE-2021-35331
ECHO-CD9D-2394-E10E
OESA-2022-1720
ROSA-SA-2024-2541
SUSE-FU-2022:0484-1
SUSE-FU-2022:0868-1

Affected Products

Alt Linux
Astra Linux
Debian
Tcl