CVE-2020-36148

MEDIUMCVSS 6.5/10EPSS 1.15%

Last modified

CVE-2020-36148 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Incorrect handling of input data in verifyAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointer dereference and segmentation fault error in case of restrictive memory protection or near NULL pointer overwrite in case of no memory restrictions (e.g. in embedded environments).. EPSS estimates a 1.15% chance of exploitation in the next 30 days.

Description

Incorrect handling of input data in verifyAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointer dereference and segmentation fault error in case of restrictive memory protection or near NULL pointer overwrite in case of no memory restrictions (e.g. in embedded environments).

Metrics

CVSS 3.1
6.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS Probability
1.15%

63.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
SymonicsLibmysofa>= 0.5, <= 1.1
FedoraprojectFedora32

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-36148?
Incorrect handling of input data in verifyAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointer dereference and segmentation fault error in case of restrictive memory protection or near NULL pointer overwrite in case of no memory restrictions (e.g. in embedded environments).
How severe is CVE-2020-36148?
CVE-2020-36148 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 1.15% probability of exploitation in the next 30 days.
How do I fix CVE-2020-36148?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-36148?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST