Incorrect handling of input data in changeAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointer dereference and segmentation fault error in case of restrictive memory protection or near NULL pointer overwrite in case of no memory restrictions (e.g. in embedded environments).
References
Link | Resource |
---|---|
https://github.com/hoene/libmysofa/issues/137 | Exploit Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RQLNZOVVONQSZZJHQVZT6NMOUUDMGBBR/ | Mailing List Third Party Advisory |
Configurations
History
10 Mar 2021, 15:36
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* | |
References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RQLNZOVVONQSZZJHQVZT6NMOUUDMGBBR/ - Mailing List, Third Party Advisory |
26 Feb 2021, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
11 Feb 2021, 17:27
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://github.com/hoene/libmysofa/issues/137 - Exploit, Third Party Advisory | |
CWE | CWE-476 | |
CVSS |
v2 : v3 : |
v2 : 4.3
v3 : 6.5 |
CPE | cpe:2.3:a:symonics:libmysofa:*:*:*:*:*:*:*:* |
08 Feb 2021, 21:47
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-02-08 21:15
Updated : 2021-03-10 15:36
NVD link : CVE-2020-36149
Mitre link : CVE-2020-36149
JSON object : View
Products Affected
fedoraproject
- fedora
symonics
- libmysofa
CWE
CWE-476
NULL Pointer Dereference