CVE-2021-35331: High severity tcl tk vulnerability
Published Jul 5, 2021
·Updated
DISPUTED In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crafted file. NOTE: multiple third parties dispute the significance of this finding.
Affected Software
1 affected component
Tcl Tcl=8.6.11
Remediation
Patch Available
Event History
Jul 5, 2021
CVE Published
via MITRE·02:59 PM
Data Sourced
via MITRE·02:59 PM
Description
Disputed
03:15 PM
Frequently Asked Questions
1
What is the severity of CVE-2021-35331?
The severity of CVE-2021-35331 is disputed, with some considering it a significant concern due to the potential for code execution.
2
How do I fix CVE-2021-35331?
To fix CVE-2021-35331, upgrading to a version of Tcl later than 8.6.11 is recommended.
3
What software is affected by CVE-2021-35331?
CVE-2021-35331 specifically affects Tcl version 8.6.11.
4
Can CVE-2021-35331 allow remote code execution?
Yes, CVE-2021-35331 could potentially allow remote code execution through a crafted file.
5
What file types are involved in CVE-2021-35331?
CVE-2021-35331 involves manipulation of files processed by the Tcl nmakehlp.c component.