PT-2021-4073 · Unknown+1 · Libgetdata+1
Pedro Sampaio
·
Published
2021-01-16
·
Updated
2024-10-17
·
CVE-2021-20204
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
libgetdata version 0.10.0
Description
The issue is related to a heap memory corruption problem, specifically a use after free error, that can be triggered when processing maliciously crafted dirfile databases. This may lead to arbitrary code execution or privilege escalation, depending on the input and skills of the attacker, and degrades the confidentiality, integrity, and availability of third-party software that uses libgetdata as a library.
Recommendations
For libgetdata version 0.10.0, consider restricting access to maliciously crafted dirfile databases to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using libgetdata to process untrusted databases.
Fix
Buffer Overflow
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Suse
Libgetdata