PT-2021-11934 · Symonics+2 · Libmysofa+2

Cve-Reporting

·

Published

2020-08-26

·

Updated

2023-10-21

·

CVE-2020-36152

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Symonics libmysofa versions 0.5 through 1.1
Description: The issue allows attackers to execute arbitrary code via a crafted SOFA file, due to a buffer overflow in the readDataVar function in hdf/dataobject.c.
Recommendations: For versions 0.5 through 1.1, consider disabling the readDataVar function until a patch is available to prevent potential exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-03910
CVE-2020-36152
OPENSUSE-SU-2021:0444-1
OPENSUSE-SU-2021:0459-1
OPENSUSE-SU-2021_0444-1
OPENSUSE-SU-2024:10960-1
ROSA-SA-2023-2256

Affected Products

Astra Linux
Suse
Libmysofa