Out-of-bounds write in tmux - CVE-2020-27347
Published: November 6, 2020 / Updated: November 18, 2020
Vulnerability identifier: #VU48517
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-27347
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local authenticated user to execute arbitrary code.
In tmux before version 3.1c the function input_csi_dispatch_sgr_colon() in file input.c contained a stack-based buffer-overflow that can be exploited by terminal output.
Affected software
tmux
Gentoo Linux
openEuler
Ubuntu
tmux (Alpine package)
tmux
tmux-help
tmux-debugsource
tmux-debuginfo
tmux (Ubuntu package)
Gentoo Linux
openEuler
Ubuntu
tmux (Alpine package)
tmux
tmux-help
tmux-debugsource
tmux-debuginfo
tmux (Ubuntu package)
How to mitigate CVE-2020-27347
Install update from vendor's website.
tmux - update to 3.1c
tmux - update to 2.9a-2
tmux-help - update to 2.9a-2
tmux-debugsource - update to 2.9a-2
tmux-debuginfo - update to 2.9a-2
tmux (Ubuntu package) - addressed in versions 3.0a-2ubuntu0.2, 3.1b-1ubuntu0.1
tmux - update to 2.9a-2
tmux-help - update to 2.9a-2
tmux-debugsource - update to 2.9a-2
tmux-debuginfo - update to 2.9a-2
tmux (Ubuntu package) - addressed in versions 3.0a-2ubuntu0.2, 3.1b-1ubuntu0.1