CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
Percentile
74.0%
DISPUTED In Tcl 8.6.11, a format string vulnerability in nmakehlp.c
might allow code execution via a crafted file. NOTE: multiple third parties
dispute the significance of this finding.
Author | Note |
---|---|
sbeattie | issue is disputed (see github tcl commit) because the format string vuln is in a build helper. |
core.tcl-lang.org/tcl/info/28ef6c0c741408a2
core.tcl-lang.org/tcl/info/bad6cc213dfe8280
github.com/tcltk/tcl/commit/4705dbdde2f32ff90420765cd93e7ac71d81a222
launchpad.net/bugs/cve/CVE-2021-35331
nvd.nist.gov/vuln/detail/CVE-2021-35331
security-tracker.debian.org/tracker/CVE-2021-35331
sqlite.org/forum/info/7dcd751996c93ec9
www.cve.org/CVERecord?id=CVE-2021-35331
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
Percentile
74.0%