CVE-2021-27135

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-27135
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-27135.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-27135
Downstream
Related
Published
2021-02-10T16:15:13Z
Modified
2025-10-21T02:34:12Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

xterm before Patch #366 allows remote attackers to execute arbitrary code or cause a denial of service (segmentation fault) via a crafted UTF-8 combining character sequence.

References

Affected packages

Git / github.com/thomasdickey/xterm-snapshots

Affected ranges

Type
GIT
Repo
https://github.com/thomasdickey/xterm-snapshots
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Database specific

vanir_signatures

[
    {
        "source": "https://github.com/thomasdickey/xterm-snapshots/commit/82ba55b8f994ab30ff561a347b82ea340ba7075c",
        "signature_version": "v1",
        "deprecated": false,
        "id": "CVE-2021-27135-a2bc9fb9",
        "target": {
            "file": "button.c"
        },
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "277148843522247792063794214364607991703",
                "16818336402220346127488010570367314038",
                "323236449147721195249215930107085499439",
                "297085073382815427472032307678603587892",
                "74882116455560791166794663649655751526",
                "325103990340651829762690253465184086568",
                "203997351473975185562593409991130104445",
                "215591782777490406855907464249939362306",
                "15713256378289495295718885869035554783",
                "153906715426697823211501509374258167069",
                "155637593777033425502821384904868628191",
                "307720885783947251490436529083262210094",
                "323820652969859190218317359477985534990",
                "101295488949237601696279946418004577908",
                "99940377818103097677378623059282468999"
            ]
        }
    },
    {
        "source": "https://github.com/thomasdickey/xterm-snapshots/commit/82ba55b8f994ab30ff561a347b82ea340ba7075c",
        "signature_version": "v1",
        "deprecated": false,
        "id": "CVE-2021-27135-f415546d",
        "target": {
            "function": "SaltTextAway",
            "file": "button.c"
        },
        "signature_type": "Function",
        "digest": {
            "length": 2116.0,
            "function_hash": "98433897814228501755533246292104164193"
        }
    }
]