CVE-2021-26937: Critical severity suse screen vulnerability
encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-26937?
CVE-2021-26937 is a vulnerability in GNU Screen through 4.8.0 that allows remote attackers to cause a denial of service or possibly have other impacts via a crafted UTF-8 character sequence.
What is the severity of CVE-2021-26937?
The severity of CVE-2021-26937 is critical with a CVSS score of 9.8.
How can I check if my GNU Screen version is affected by CVE-2021-26937?
To check if your GNU Screen version is affected by CVE-2021-26937, you can refer to the official GNU Screen website or the Debian security advisory for the affected versions.
How do I fix CVE-2021-26937?
To fix CVE-2021-26937, you should update to GNU Screen version 4.8.0-4 or any patched versions provided by your operating system vendor.
Are there any references for CVE-2021-26937?
Yes, you can find references for CVE-2021-26937 at the following URLs: http://www.openwall.com/lists/oss-security/2021/02/09/8, https://ftp.gnu.org/gnu/screen/, https://lists.debian.org/debian-lts-announce/2021/02/msg00031.html