« Volver al listado

CVE-2020-27347

Estado: ModificadaAlta (7.8)—

In tmux before version 3.1c the function input_csi_dispatch_sgr_colon() in file input.c contained a stack-based buffer-overflow that can be exploited by terminal output.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-27347",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@ubuntu.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@ubuntu.com",
      "affectedData": [
        {
          "vendor": "tmux",
          "product": "tmux",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "3.1c",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Ubuntu",
          "product": "tmux",
          "versions": [
            {
              "status": "affected",
              "version": "3.1b",
              "lessThan": "3.1b-1ubuntu0.1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.0a",
              "lessThan": "3.0a-2ubuntu0.2",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-11-06T03:15:17.137",
  "references": [
    {
      "url": "https://github.com/tmux/tmux/commit/a868bacb46e3c900530bed47a1c6f85b0fbe701c",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "https://raw.githubusercontent.com/tmux/tmux/3.1c/CHANGES",
      "tags": [
        "Release Notes",
        "Third Party Advisory"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "https://security.gentoo.org/glsa/202011-10",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "https://www.openwall.com/lists/oss-security/2020/11/05/3",
      "tags": [
        "Exploit",
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "https://github.com/tmux/tmux/commit/a868bacb46e3c900530bed47a1c6f85b0fbe701c",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://raw.githubusercontent.com/tmux/tmux/3.1c/CHANGES",
      "tags": [
        "Release Notes",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.gentoo.org/glsa/202011-10",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.openwall.com/lists/oss-security/2020/11/05/3",
      "tags": [
        "Exploit",
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@ubuntu.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-121"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In tmux before version 3.1c the function input_csi_dispatch_sgr_colon() in file input.c contained a stack-based buffer-overflow that can be exploited by terminal output."
    },
    {
      "lang": "es",
      "value": "En tmux anterior a la versión 3.1c la función input_csi_dispatch_sgr_colon() en el archivo input.c contenía un desbordamiento de búfer en la región stack de la memoria que puede ser explotado mediante la salida del terminal"
    }
  ],
  "lastModified": "2026-06-17T03:09:09.370",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:tmux_project:tmux:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "604BA314-EFDC-4F3A-9C98-8A9119D57196",
              "versionEndIncluding": "3.1b",
              "versionStartIncluding": "2.9"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@ubuntu.com"
}