In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crafted file. NOTE: multiple third parties dispute the significance of this finding
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-35331.json"
[
{
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/tcltk/tcl/commit/4705dbdde2f32ff90420765cd93e7ac71d81a222",
"digest": {
"line_hashes": [
"338794718477778830788026938893809680996",
"167523017892673006030716419150005314888",
"255738228804160061589439085284092356741",
"128920200318728874743013425295381636087",
"76778023355815920090853215777728435607",
"105858589626416364655426904205864977080",
"172666521847550365368341013690159064849",
"307508334135556441185366936693295759738"
],
"threshold": 0.9
},
"id": "CVE-2021-35331-03722e49",
"deprecated": false,
"target": {
"file": "win/nmakehlp.c"
}
},
{
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/tcltk/tcl/commit/4705dbdde2f32ff90420765cd93e7ac71d81a222",
"digest": {
"function_hash": "79655282905794098102193868097258390460",
"length": 1577.0
},
"id": "CVE-2021-35331-73057c0f",
"deprecated": false,
"target": {
"file": "win/nmakehlp.c",
"function": "SubstituteFile"
}
}
]