PT-2020-20741 · Lg Electronics+3 · Web Os Tv Emulator+3

Published

2020-03-23

·

Updated

2022-04-22

·

CVE-2020-9759

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions LG Electronic web OS TV Emulator (affected versions not specified) WeeChat versions 0.4.0 through 2.7
Description The issue is related to a wrong environment setting that could allow an attacker to escalate privileges and overwrite certain files through crafted configuration files and executable files. Additionally, a malformed message can cause a NULL pointer dereference in the callback function, resulting in a crash.
Recommendations For LG Electronic web OS TV Emulator, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For WeeChat versions 0.4.0 through 2.7, update to version 2.7.1 or later to resolve the issue.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-9759
DLA-2157-1
DLA-2770-1
MGASA-2020-0153
USN-5258-1

Affected Products

Linuxmint
Ubuntu
Weechat
Web Os Tv Emulator