Denial of Service Vulnerability in GNU Screen By GNU
CVE-2021-26937

9.8CRITICAL

Key Information:

Vendor
Gnu
Status
Vendor
CVE Published:
9 February 2021

Summary

The vulnerability allows remote attackers to exploit GNU Screen versions through crafted UTF-8 character sequences, leading to invalid write access. This can result in application crashes and potential disruption of service. The issue arises from improper handling of character input in encoding.c, which can cause instability and shutdowns in applications using this terminal multiplexer. Users are advised to upgrade to the latest patched version to mitigate risk.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.