Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-20204

Опубликовано: 06 мая 2021
Источник: debian
EPSS Низкий

Описание

A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This degrades the confidentiality, integrity and availability of third-party software that uses libgetdata as a library. This vulnerability may lead to arbitrary code execution or privilege escalation depending on input/skills of attacker.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libgetdatafixed0.10.0-10package
libgetdatafixed0.10.0-5+deb10u1busterpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1956348

  • https://bugs.launchpad.net/ubuntu/+source/libgetdata/+bug/1912050

  • Debian patch applied causes functional regressions: https://bugs.debian.org/992437

EPSS

Процентиль: 85%
0.02335
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 5 лет назад

A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This degrades the confidentiality, integrity and availability of third-party software that uses libgetdata as a library. This vulnerability may lead to arbitrary code execution or privilege escalation depending on input/skills of attacker.

CVSS3: 9.8
nvd
почти 5 лет назад

A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This degrades the confidentiality, integrity and availability of third-party software that uses libgetdata as a library. This vulnerability may lead to arbitrary code execution or privilege escalation depending on input/skills of attacker.

suse-cvrf
около 4 лет назад

Security update for getdata

CVSS3: 9.8
github
больше 3 лет назад

A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This degrades the confidentiality, integrity and availability of third-party software that uses libgetdata as a library. This vulnerability may lead to arbitrary code execution or privilege escalation depending on input/skills of attacker.

CVSS3: 9.8
fstec
около 5 лет назад

Уязвимость СУБД GetData, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 85%
0.02335
Низкий