ALT-PU-2021-4714-1
Closed vulnerabilities
Published: 2021-02-09
BDU:2021-03746
Уязвимость компонента encoding.c оконного менеджера GNU Screen, связанная с внедрением или модификацией аргумента, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Severity: CRITICAL (9.8)
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
Published: 2021-02-09
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2021-26937
encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence.
Severity: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
- [oss-security] 20210210 Re: screen crash processing combining characters
- [oss-security] 20210210 Re: screen crash processing combining characters
- https://ftp.gnu.org/gnu/screen/
- https://ftp.gnu.org/gnu/screen/
- [debian-lts-announce] 20210219 [SECURITY] [DLA 2570-1] screen security update
- [debian-lts-announce] 20210219 [SECURITY] [DLA 2570-1] screen security update
- FEDORA-2021-9107eeb95c
- FEDORA-2021-9107eeb95c
- FEDORA-2021-5e9894a0c5
- FEDORA-2021-5e9894a0c5
- https://lists.gnu.org/archive/html/screen-devel/2021-02/msg00000.html
- https://lists.gnu.org/archive/html/screen-devel/2021-02/msg00000.html
- GLSA-202105-11
- GLSA-202105-11
- DSA-4861
- DSA-4861
- https://www.openwall.com/lists/oss-security/2021/02/09/3
- https://www.openwall.com/lists/oss-security/2021/02/09/3