Improper Neutralization of Argument Delimiters in a Command in Screen - CVE-2021-26937

 

Improper Neutralization of Argument Delimiters in a Command in Screen - CVE-2021-26937

Published: February 22, 2021


Vulnerability identifier: #VU50842
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-26937
CWE-ID: CWE-88
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to incorrect processing of user-supplied data in the encoding.c file. A remote attacker can pass specially crafted UTF-8 character sequence to the GNU Screen application and perform a denial of service attack or execute arbitrary code on the system.


Affected software

Screen
Data Computing Appliance (DCA)
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Fedora
Ubuntu
openEuler
screen (Debian package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
screen (Red Hat package)
screen (Ubuntu package)
screen
screen-debugsource
screen-debuginfo
screen-help
Juniper Junos Space

How to mitigate CVE-2021-26937

Install updates from vendor's website.

screen (Debian package) - update to 4.6.2-3+deb10u1
screen (Red Hat package) - addressed in versions 4.1.0-0.25.20120314git3c2946.el7_7.1, 4.1.0-0.27.20120314git3c2946.el7_9
screen (Ubuntu package) - addressed in versions 4.1.0~20120320gitdb59704-9ubuntu0.1~esm2, 4.3.1-2ubuntu0.1, 4.6.2-1ubuntu1.1, 4.8.0-1ubuntu0.1, 4.8.0-2ubuntu0.1
Data Computing Appliance (DCA) - update to 4.3.0.0
screen - addressed in versions 4.6.2-12.el8, 4.8.0-5.fc32, 4.8.0-5.fc33
screen - update to 4.8.0-2
screen-debugsource - update to 4.8.0-2
screen-debuginfo - update to 4.8.0-2
screen-help - update to 4.8.0-2
Juniper Junos Space - update to 21.2R1

External References

Related Security Bulletins