In tmux before version 3.1c the function inputcsidispatchsgrcolon() in file input.c contained a stack-based buffer-overflow that can be exploited by terminal output.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-27347.json"
[
{
"source": "https://github.com/tmux/tmux/commit/a868bacb46e3c900530bed47a1c6f85b0fbe701c",
"id": "CVE-2020-27347-4e35a636",
"signature_type": "Function",
"signature_version": "v1",
"target": {
"file": "input.c",
"function": "input_csi_dispatch_sgr_colon"
},
"deprecated": false,
"digest": {
"function_hash": "170732737008620410805361164261211254853",
"length": 1720.0
}
},
{
"source": "https://github.com/tmux/tmux/commit/a868bacb46e3c900530bed47a1c6f85b0fbe701c",
"id": "CVE-2020-27347-c15704b2",
"signature_type": "Line",
"signature_version": "v1",
"target": {
"file": "input.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"240113919815530745566403619576218062793",
"77253474740385740734274446039228610202",
"174889705706748848756308818781097816062",
"12643815915660841977168808069864222592",
"125294518473082047418332633995689035105"
],
"threshold": 0.9
}
}
]