In tmux before version 3.1c the function input_csi_dispatch_sgr_colon() in file input.c contained a stack-based buffer-overflow that can be exploited by terminal output.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-tmux | Jan 4, 2021 | Nov 6, 2020 | |
| Debian | debian-upgrade-tmux | Jul 30, 2024 | Nov 6, 2020 | |
| Gentoo Linux | gentoo-linux-upgrade-app-misc-tmux | Nov 12, 2020 | Nov 6, 2020 | |
| Huawei Euleros 2_0_sp8 | huawei-euleros-2_0_sp8-upgrade-tmux | Dec 15, 2020 | Nov 6, 2020 | |
| Huawei Euleros 2_0_sp9 | huawei-euleros-2_0_sp9-upgrade-tmux-help | Dec 1, 2020 | Nov 6, 2020 | |
| Oracle Solaris | oracle-solaris-11-4-upgrade-terminal-tmux-3-1-3-11-4-28-0-1-82-2 | Jan 19, 2021 | Nov 6, 2020 | |
| Suse | — | suse-upgrade-tmux | Jun 16, 2021 | Nov 6, 2020 |
| Ubuntu | ubuntu-upgrade-tmux | Mar 22, 2023 | Nov 6, 2020 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Nov 6, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub