CVE Vulnerabilities

CVE-2020-36148

NULL Pointer Dereference

Published: Feb 08, 2021 | Modified: Nov 07, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

Incorrect handling of input data in verifyAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointer dereference and segmentation fault error in case of restrictive memory protection or near NULL pointer overwrite in case of no memory restrictions (e.g. in embedded environments).

Weakness

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Affected Software

Name Vendor Start Version End Version
Libmysofa Symonics 0.5 (including) 1.1 (including)
Libmysofa Ubuntu bionic *
Libmysofa Ubuntu esm-apps/bionic *
Libmysofa Ubuntu esm-apps/focal *
Libmysofa Ubuntu focal *
Libmysofa Ubuntu groovy *
Libmysofa Ubuntu hirsute *
Libmysofa Ubuntu impish *
Libmysofa Ubuntu jammy *
Libmysofa Ubuntu trusty *
Libmysofa Ubuntu upstream *

Potential Mitigations

References