CVE-2020-28951

libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package names. This is related to uci_parse_package in file.c and uci_strdup in util.c.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:openwrt:openwrt:*:*:*:*:*:*:*:*
cpe:2.3:o:openwrt:openwrt:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:21

Type Values Removed Values Added
References
  • {'url': 'https://git.openwrt.org/?p=openwrt/openwrt.git;a=commit;h=5625f5bc36954d644cb80adf8de47854c65d91c3', 'name': 'https://git.openwrt.org/?p=openwrt/openwrt.git;a=commit;h=5625f5bc36954d644cb80adf8de47854c65d91c3', 'tags': ['Patch', 'Vendor Advisory'], 'refsource': 'MISC'}
  • {'url': 'https://git.openwrt.org/?p=openwrt/openwrt.git;a=log;h=refs/tags/v18.06.9', 'name': 'https://git.openwrt.org/?p=openwrt/openwrt.git;a=log;h=refs/tags/v18.06.9', 'tags': ['Patch', 'Vendor Advisory'], 'refsource': 'MISC'}
  • {'url': 'https://git.openwrt.org/?p=project/uci.git;a=commit;h=a3e650911f5e6f67dcff09974df3775dfd615da6', 'name': 'https://git.openwrt.org/?p=project/uci.git;a=commit;h=a3e650911f5e6f67dcff09974df3775dfd615da6', 'tags': ['Patch', 'Vendor Advisory'], 'refsource': 'MISC'}
  • () https://git.openwrt.org/?p=project/uci.git%3Ba=commit%3Bh=a3e650911f5e6f67dcff09974df3775dfd615da6 -
  • () https://git.openwrt.org/?p=openwrt/openwrt.git%3Ba=commit%3Bh=5625f5bc36954d644cb80adf8de47854c65d91c3 -
  • () https://git.openwrt.org/?p=openwrt/openwrt.git%3Ba=log%3Bh=refs/tags/v18.06.9 -

24 May 2023, 15:01

Type Values Removed Values Added
CPE cpe:2.3:a:openwrt:openwrt:*:*:*:*:*:*:*:* cpe:2.3:o:openwrt:openwrt:*:*:*:*:*:*:*:*

Information

Published : 2020-11-19 19:15

Updated : 2023-12-10 13:41


NVD link : CVE-2020-28951

Mitre link : CVE-2020-28951

CVE.ORG link : CVE-2020-28951


JSON object : View

Products Affected

openwrt

  • openwrt
CWE
CWE-416

Use After Free