Vulnerability CVE-2021-26937: Information

Description

encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence.

Severity: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Published: Feb. 9, 2021
Modified: Nov. 7, 2023
Error type identifier: CWE-88

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
screensisyphus4.8.0-alt24.8.0-alt2ALT-PU-2021-3263-1263893Fixed
screensisyphus_e2k4.8.0-alt24.8.0-alt2ALT-PU-2022-3454-1-Fixed
screenp104.8.0-alt24.8.0-alt2ALT-PU-2021-3614-1291984Fixed
screenp10_e2k4.8.0-alt24.8.0-alt2ALT-PU-2021-4714-1-Fixed
screenc10f14.8.0-alt24.8.0-alt2ALT-PU-2021-3614-1291984Fixed
screenc9f24.6.2-alt3.p9.24.6.2-alt3.p9.2ALT-PU-2021-3266-1289403Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:gnu:screen:*:*:*:*:*:*:*:*

      Configuration 2

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*