CVE-2021-35331

** DISPUTED ** In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crated file. NOTE: multiple third parties dispute the significance of this finding.

Summary:

** DISPUTED ** In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crated file. NOTE: multiple third parties dispute the significance of this finding.

Reference Links(if available):

  • https://core.tcl-lang.org/tcl/info/28ef6c0c741408a2
  • https://core.tcl-lang.org/tcl/info/bad6cc213dfe8280
  • https://github.com/tcltk/tcl/commit/4705dbdde2f32ff90420765cd93e7ac71d81a222
  • https://sqlite.org/forum/info/7dcd751996c93ec9
  • CVSS Score (if available)

    v2: / MEDIUM

    v3: /

    Links to Exploits(if available)