PT-2020-9617 · Unknown · Newlib Libc

Dimitrios Glynos

·

Published

2020-03-19

·

Updated

2020-03-24

·

CVE-2019-14878

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions newlib libc library versions prior to 3.3.0
Description The issue arises in the d2b function of the newlib libc library, where Balloc is used to allocate a big integer without verifying if the allocation was successful. This can lead to a null pointer dereference bug when accessing x in case of a memory allocation failure.
Recommendations For versions prior to 3.3.0, update to version 3.3.0 or later to resolve the issue.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-14878

Affected Products

Newlib Libc