CVE-2020-36619

A vulnerability was found in multimon-ng. It has been rated as critical. This issue affects the function add_ch of the file demod_flex.c. The manipulation of the argument ch leads to format string. Upgrading to version 1.2.0 is able to address this issue. The name of the patch is e5a51c508ef952e81a6da25b43034dd1ed023c07. It is recommended to upgrade the affected component. The identifier VDB-216269 was assigned to this vulnerability.
References
Link Resource
https://github.com/EliasOenal/multimon-ng/commit/e5a51c508ef952e81a6da25b43034dd1ed023c07 Patch Third Party Advisory
https://github.com/EliasOenal/multimon-ng/pull/160 Patch Third Party Advisory
https://github.com/EliasOenal/multimon-ng/releases/tag/1.2.0 Release Notes Third Party Advisory
https://vuldb.com/?id.216269 Permissions Required Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:multimon-ng_project:multimon-ng:*:*:*:*:*:*:*:*

History

27 Dec 2022, 17:52

Type Values Removed Values Added
References (N/A) https://github.com/EliasOenal/multimon-ng/releases/tag/1.2.0 - (N/A) https://github.com/EliasOenal/multimon-ng/releases/tag/1.2.0 - Release Notes, Third Party Advisory
References (N/A) https://github.com/EliasOenal/multimon-ng/commit/e5a51c508ef952e81a6da25b43034dd1ed023c07 - (N/A) https://github.com/EliasOenal/multimon-ng/commit/e5a51c508ef952e81a6da25b43034dd1ed023c07 - Patch, Third Party Advisory
References (N/A) https://vuldb.com/?id.216269 - (N/A) https://vuldb.com/?id.216269 - Permissions Required, Third Party Advisory, VDB Entry
References (N/A) https://github.com/EliasOenal/multimon-ng/pull/160 - (N/A) https://github.com/EliasOenal/multimon-ng/pull/160 - Patch, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Multimon-ng Project
Multimon-ng Project multimon-ng
CPE cpe:2.3:a:multimon-ng_project:multimon-ng:*:*:*:*:*:*:*:*
CWE CWE-119

19 Dec 2022, 14:18

Type Values Removed Values Added
New CVE

Information

Published : 2022-12-19 14:15

Updated : 2023-12-10 14:48


NVD link : CVE-2020-36619

Mitre link : CVE-2020-36619

CVE.ORG link : CVE-2020-36619


JSON object : View

Products Affected

multimon-ng_project

  • multimon-ng
CWE
CWE-134

Use of Externally-Controlled Format String

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer