Improper Neutralization of Argument Delimiters in a Command in Screen - CVE-2021-26937
Published: February 22, 2021
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to incorrect processing of user-supplied data in the encoding.c file. A remote attacker can pass specially crafted UTF-8 character sequence to the GNU Screen application and perform a denial of service attack or execute arbitrary code on the system.
Affected software
Data Computing Appliance (DCA)
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Fedora
Ubuntu
openEuler
screen (Debian package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
screen (Red Hat package)
screen (Ubuntu package)
screen
screen-debugsource
screen-debuginfo
screen-help
Juniper Junos Space
How to mitigate CVE-2021-26937
screen (Red Hat package) - addressed in versions 4.1.0-0.25.20120314git3c2946.el7_7.1, 4.1.0-0.27.20120314git3c2946.el7_9
screen (Ubuntu package) - addressed in versions 4.1.0~20120320gitdb59704-9ubuntu0.1~esm2, 4.3.1-2ubuntu0.1, 4.6.2-1ubuntu1.1, 4.8.0-1ubuntu0.1, 4.8.0-2ubuntu0.1
Data Computing Appliance (DCA) - update to 4.3.0.0
screen - addressed in versions 4.6.2-12.el8, 4.8.0-5.fc32, 4.8.0-5.fc33
screen - update to 4.8.0-2
screen-debugsource - update to 4.8.0-2
screen-debuginfo - update to 4.8.0-2
screen-help - update to 4.8.0-2
Juniper Junos Space - update to 21.2R1
External References
Related Security Bulletins
- Remote code execution in GNU Screen
- Debian update for screen
- Red Hat Enterprise Linux 7 update for screen
- Amazon Linux AMI update for screen
- Gentoo update for GNU Screen
- Multiple vulnerabilities in Junos Space
- Red Hat Enterprise Linux 7.7 update for screen
- Ubuntu update for screen
- Ubuntu update for screen
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- openEuler update for screen
- Fedora 33 update for screen
- Fedora 32 update for screen
- Fedora EPEL 8 update for screen