{"id":"CVE-2020-27347","details":"In tmux before version 3.1c the function input_csi_dispatch_sgr_colon() in file input.c contained a stack-based buffer-overflow that can be exploited by terminal output.","modified":"2026-05-18T13:01:24.318517Z","published":"2020-11-06T03:15:17.137Z","related":["openSUSE-SU-2020:1834-1","openSUSE-SU-2024:11466-1"],"references":[{"type":"ADVISORY","url":"https://raw.githubusercontent.com/tmux/tmux/3.1c/CHANGES"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202011-10"},{"type":"FIX","url":"https://github.com/tmux/tmux/commit/a868bacb46e3c900530bed47a1c6f85b0fbe701c"},{"type":"EVIDENCE","url":"https://www.openwall.com/lists/oss-security/2020/11/05/3"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tmux/tmux","events":[{"introduced":"4cb13d95bac1c7a14f216a0fd1644d8b5e389258"},{"last_affected":"25cae5d86f01d0deb050243842ed5d967b3dc411"}],"database_specific":{"source":"CPE_FIELD","cpe":"cpe:2.3:a:tmux_project:tmux:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.9"},{"last_affected":"3.1b"}]}}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-27347.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}