{"id":"CVE-2021-35331","details":"In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crafted file. NOTE: multiple third parties dispute the significance of this finding","modified":"2026-07-08T23:58:05.811850Z","published":"2021-07-05T15:15:07.997Z","related":["SUSE-FU-2022:0484-1","SUSE-FU-2022:0868-1"],"references":[{"type":"FIX","url":"https://core.tcl-lang.org/tcl/info/28ef6c0c741408a2"},{"type":"FIX","url":"https://github.com/tcltk/tcl/commit/4705dbdde2f32ff90420765cd93e7ac71d81a222"},{"type":"EVIDENCE","url":"https://core.tcl-lang.org/tcl/info/bad6cc213dfe8280"},{"type":"EVIDENCE","url":"https://sqlite.org/forum/info/7dcd751996c93ec9"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tcltk/tcl","events":[{"introduced":"17b5b3e0201cdf92d3c125776e1b2dd453f225bd"},{"last_affected":"17b5b3e0201cdf92d3c125776e1b2dd453f225bd"},{"fixed":"4705dbdde2f32ff90420765cd93e7ac71d81a222"}],"database_specific":{"cpe":"cpe:2.3:a:tcl:tcl:8.6.11:*:*:*:*:*:*:*","extracted_events":[{"introduced":"8.6.11"},{"last_affected":"8.6.11"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["8.6.11","core-8-6-11"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-35331.json","vanir_signatures_modified":"2026-07-08T23:58:05Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["338794718477778830788026938893809680996","167523017892673006030716419150005314888","255738228804160061589439085284092356741","128920200318728874743013425295381636087","76778023355815920090853215777728435607","105858589626416364655426904205864977080","172666521847550365368341013690159064849","307508334135556441185366936693295759738"],"threshold":0.9},"id":"CVE-2021-35331-03722e49","signature_type":"Line","signature_version":"v1","source":"https://github.com/tcltk/tcl/commit/4705dbdde2f32ff90420765cd93e7ac71d81a222","target":{"file":"win/nmakehlp.c"}},{"target":{"file":"win/nmakehlp.c","function":"SubstituteFile"},"deprecated":false,"digest":{"function_hash":"79655282905794098102193868097258390460","length":1577},"id":"CVE-2021-35331-73057c0f","signature_type":"Function","signature_version":"v1","source":"https://github.com/tcltk/tcl/commit/4705dbdde2f32ff90420765cd93e7ac71d81a222"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}