7.5
CVSSv2

CVE-2021-26937

Published: 09/02/2021 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

encoding.c in GNU Screen up to and including 4.8.0 allows remote malicious users to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu screen

debian debian linux 9.0

debian debian linux 10.0

fedoraproject fedora 32

fedoraproject fedora 33

Vendor Advisories

Synopsis Important: screen security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for screen is now available for Red Hat Enterprise Linux 77 Advanced Update Support, Red Hat Enterprise Linux 77 Telco ...
Debian Bug report logs - #982435 screen: CVE-2021-26937 Package: src:screen; Maintainer for src:screen is Axel Beckert <abe@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 10 Feb 2021 10:00:01 UTC Severity: grave Tags: confirmed, security, upstream Found in versions screen/450-6, scre ...
Felix Weinmann reported a flaw in the handling of combining characters in screen, a terminal multiplexer with VT100/ANSI terminal emulation, which can result in denial of service, or potentially the execution of arbitrary code via a specially crafted UTF-8 character sequence For the stable distribution (buster), this problem has been fixed in vers ...
A flaw was found in screen A specially crafted sequence of combining characters could cause an out of bounds write leading to arbitrary code execution The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability (CVE-2021-26937) ...
A flaw was found in screen A specially crafted sequence of combining characters could cause an out of bounds write leading to arbitrary code execution The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability (CVE-2021-26937) ...
encodingc in GNU Screen through 480 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Re: screen crash processing combining characters <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Utkarsh Gupta &l ...