PT-2021-4073 · Unknown+1 · Libgetdata+1

Pedro Sampaio

·

Published

2021-01-16

·

Updated

2024-10-17

·

CVE-2021-20204

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libgetdata version 0.10.0
Description The issue is related to a heap memory corruption problem, specifically a use after free error, that can be triggered when processing maliciously crafted dirfile databases. This may lead to arbitrary code execution or privilege escalation, depending on the input and skills of the attacker, and degrades the confidentiality, integrity, and availability of third-party software that uses libgetdata as a library.
Recommendations For libgetdata version 0.10.0, consider restricting access to maliciously crafted dirfile databases to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using libgetdata to process untrusted databases.

Fix

Buffer Overflow

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2021-04647
CVE-2021-20204
DLA-2660-1
OPENSUSE-SU-2021:1645-1
OPENSUSE-SU-2021_1645-1

Affected Products

Suse
Libgetdata