Vulnerability Description
In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crafted file. NOTE: multiple third parties dispute the significance of this finding
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tcl | Tcl | 8.6.11 |
Related Weaknesses (CWE)
References
- https://core.tcl-lang.org/tcl/info/28ef6c0c741408a2ExploitPatchVendor Advisory
- https://core.tcl-lang.org/tcl/info/bad6cc213dfe8280ExploitVendor Advisory
- https://github.com/tcltk/tcl/commit/4705dbdde2f32ff90420765cd93e7ac71d81a222PatchThird Party Advisory
- https://sqlite.org/forum/info/7dcd751996c93ec9ExploitThird Party Advisory
- https://core.tcl-lang.org/tcl/info/28ef6c0c741408a2ExploitPatchVendor Advisory
- https://core.tcl-lang.org/tcl/info/bad6cc213dfe8280ExploitVendor Advisory
- https://github.com/tcltk/tcl/commit/4705dbdde2f32ff90420765cd93e7ac71d81a222PatchThird Party Advisory
- https://sqlite.org/forum/info/7dcd751996c93ec9ExploitThird Party Advisory
FAQ
What is CVE-2021-35331?
CVE-2021-35331 is a vulnerability with a CVSS score of 7.8 (HIGH). In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crafted file. NOTE: multiple third parties dispute the significance of this finding
How severe is CVE-2021-35331?
CVE-2021-35331 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-35331?
Check the references section above for vendor advisories and patch information. Affected products include: Tcl Tcl.