PT-2020-14442 · Ntop · Ndpi

Published

2020-07-01

·

Updated

2020-07-06

·

CVE-2020-15475

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions nDPI versions prior to 3.2
Description The issue arises from the ndpi reset packet line info function in lib/ndpi main.c, which fails to properly reinitialize certain data, resulting in a use-after-free situation.
Recommendations For versions prior to 3.2, consider updating to a version that includes the necessary reinitialization in the ndpi reset packet line info function to prevent the use-after-free issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15475

Affected Products

Ndpi