In tmux before version 3.1c the function input_csi_dispatch_sgr_colon() in file input.c contained a stack-based buffer-overflow that can be exploited by terminal output.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade tmux | Jan 4, 2021 | Nov 6, 2020 |
| Debian | — | Upgrade tmux | Jul 30, 2024 | Nov 6, 2020 |
| Gentoo Linux | — | Upgrade app-misc/tmux. | Nov 12, 2020 | Nov 6, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade tmux | Dec 15, 2020 | Nov 6, 2020 |
| Huawei Euleros 2_0_sp9 | — | Upgrade tmux-help | Dec 1, 2020 | Nov 6, 2020 |
| Oracle Solaris | — | Upgrade terminal/tmux to version 3.1.3-11.4.28.0.1.82.2 on Solaris 11.4 | Jan 19, 2021 | Nov 6, 2020 |
| Suse | — | Upgrade tmux | Jun 16, 2021 | Nov 6, 2020 |
| Ubuntu | — | Upgrade tmux | Mar 22, 2023 | Nov 6, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Nov 6, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub