CVE-2021-35331

Source
https://cve.org/CVERecord?id=CVE-2021-35331
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-35331.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-35331
Downstream
BELL (1)
DEBIAN (1)
ECHO (1)
OESA (1)
ROOT (1)
SUSE (2)
Related
Published
2021-07-05T15:15:07Z
Modified
2026-07-08T23:58:05Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crafted file. NOTE: multiple third parties dispute the significance of this finding

References

Affected packages

Git / github.com/tcltk/tcl

Affected ranges

Type
GIT
Repo
https://github.com/tcltk/tcl
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:tcl:tcl:8.6.11:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "8.6.11"
        },
        {
            "last_affected":  "8.6.11"
        }
    ],
    "source":  [
        "CPE_STRING",
        "REFERENCES"
    ]
}

Affected versions

8.*
8.6.11
Other
core-8-6-11

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-35331.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "338794718477778830788026938893809680996",
                "167523017892673006030716419150005314888",
                "255738228804160061589439085284092356741",
                "128920200318728874743013425295381636087",
                "76778023355815920090853215777728435607",
                "105858589626416364655426904205864977080",
                "172666521847550365368341013690159064849",
                "307508334135556441185366936693295759738"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2021-35331-03722e49",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/tcltk/tcl/commit/4705dbdde2f32ff90420765cd93e7ac71d81a222",
        "target":  {
            "file":  "win/nmakehlp.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "79655282905794098102193868097258390460",
            "length":  1577
        },
        "id":  "CVE-2021-35331-73057c0f",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/tcltk/tcl/commit/4705dbdde2f32ff90420765cd93e7ac71d81a222",
        "target":  {
            "file":  "win/nmakehlp.c",
            "function":  "SubstituteFile"
        }
    }
]
vanir_signatures_modified
"2026-07-08T23:58:05Z"