First published: Mon Jul 05 2021(Updated: )
** DISPUTED ** In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crafted file. NOTE: multiple third parties dispute the significance of this finding.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tcl Tk | =8.6.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-35331 is disputed, with some considering it a significant concern due to the potential for code execution.
To fix CVE-2021-35331, upgrading to a version of Tcl later than 8.6.11 is recommended.
CVE-2021-35331 specifically affects Tcl version 8.6.11.
Yes, CVE-2021-35331 could potentially allow remote code execution through a crafted file.
CVE-2021-35331 involves manipulation of files processed by the Tcl nmakehlp.c component.