#VU50842 Improper Neutralization of Argument Delimiters in a Command in Screen - CVE-2021-26937
Published: February 22, 2021
Screen
GNU
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to incorrect processing of user-supplied data in the encoding.c file. A remote attacker can pass specially crafted UTF-8 character sequence to the GNU Screen application and perform a denial of service attack or execute arbitrary code on the system.