PT-2021-6505 · Libpff · Libpff

Hongxuchen

·

Published

2021-08-19

·

Updated

2021-08-23

·

CVE-2020-18897

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Libpff versions prior to 20180623
Description The issue is related to an use-after-free vulnerability in the libpff item tree create node function, which allows attackers to cause a denial of service or execute arbitrary code via a crafted pff file. This vulnerability can also lead to unauthorized access to confidential data and disruption of data integrity.
Recommendations For versions prior to 20180623, update to a version released after 20180623 to resolve the issue. As a temporary workaround, consider restricting the use of the libpff item tree create node function until a patch is available. Avoid using crafted pff files to minimize the risk of exploitation.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01763
CVE-2020-18897

Affected Products

Libpff