CVE Vulnerabilities

CVE-2020-36149

NULL Pointer Dereference

Published: Feb 08, 2021 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Incorrect handling of input data in changeAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointer dereference and segmentation fault error in case of restrictive memory protection or near NULL pointer overwrite in case of no memory restrictions (e.g. in embedded environments).

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
LibmysofaSymonics0.5 (including)1.1 (including)
LibmysofaUbuntubionic*
LibmysofaUbuntuesm-apps/bionic*
LibmysofaUbuntuesm-apps/focal*
LibmysofaUbuntuesm-apps/jammy*
LibmysofaUbuntufocal*
LibmysofaUbuntugroovy*
LibmysofaUbuntuhirsute*
LibmysofaUbuntuimpish*
LibmysofaUbuntujammy*
LibmysofaUbuntutrusty*
LibmysofaUbuntuupstream*

Potential Mitigations

References