CVE-2026-58317
Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a result, the contents of adjacent memory regions may be transmitted to the server, and Tera Term may behave unexpected or terminate abnormally.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.32%
- CWE
- CWE-196
- Published
- 2026-07-17
- Last modified
- 2026-07-17
Affected products
- TeraTerm Project TTSSH2
Weakness type
Related vulnerabilities
- CVE-2026-14454 — Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed
- CVE-2026-34155 — RAUC: Improper Signing of Plain Bundles Exceeding 2 GiB
- CVE-2023-0185 — NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where sign...
- CVE-2022-36025 — Incorrect Conversion between Numeric Types in Besu Ethereum Client
- CVE-2020-13545 — An exploitable signed conversion vulnerability exists in the TextMaker document parsing...
- CVE-2020-7067 — OOB Read in urldecode()