In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crafted file. NOTE: multiple third parties dispute the significance of this finding
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Tcl | Tcl | 8.6.11 (including) | 8.6.11 (including) |
Tcl8.6 | Ubuntu | bionic | * |
Tcl8.6 | Ubuntu | groovy | * |
Tcl8.6 | Ubuntu | hirsute | * |
Tcl8.6 | Ubuntu | impish | * |
Tcl8.6 | Ubuntu | kinetic | * |
Tcl8.6 | Ubuntu | trusty | * |
Tcl8.6 | Ubuntu | xenial | * |