CVE-2020-27347

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
06/11/2020
Last modified:
18/10/2022

Description

In tmux before version 3.1c the function input_csi_dispatch_sgr_colon() in file input.c contained a stack-based buffer-overflow that can be exploited by terminal output.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tmux_project:tmux:*:*:*:*:*:*:*:* 2.9 (including) 3.1b (including)