QID 670876
QID 670876: EulerOS Security Update for tmux (EulerOS-SA-2020-2537)
tmux is a "terminal multiplexer." It enables a number of terminals (or windows) to be accessed and controlled from a single terminal. tmux is intended to be a simple, modern, BSD-licensed alternative to programs such as GNU Screen.
Security Fix(es):
In tmux before version 3.1c the function input_csi_dispatch_sgr_colon() in file input.c contained a stack-based buffer-overflow that can be exploited by terminal output.(CVE-2020-27347)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
An arbitrary attacker may exploit this vulnerability to compromise the system.
Solution
The Vendor has released a security update to fix the vulnerability. For more information please visit EulerOS-SA-2020-2537 for updates and patch information
Vendor References
CVEs related to QID 670876
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| EulerOS-SA-2020-2537 | EulerOS V2.0SP8 |
|