CVE-2019-20016
Summary
| CVE | CVE-2019-20016 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-12-27 02:15:00 UTC |
| Updated | 2020-01-08 21:22:00 UTC |
| Description | libmysofa before 2019-11-24 does not properly restrict recursive function calls, as demonstrated by reports of stack consumption in readOHDRHeaderMessageDatatype in dataobject.c and directblockRead in fractalhead.c. NOTE: a download of v0.9 after 2019-12-06 should fully remediate this issue. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fixed recursive function calls · hoene/libmysofa@2e6fac6 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| There is a stack-based buffer overflow in the readOHDRHeaderMessageDatatype function of dataobject.c(at 216) · Issue #84 · hoene/libmysofa · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| There is a stack-based buffer overflow in the directblockRead function of fractalhead.c(at 172) · Issue #83 · hoene/libmysofa · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 750304 OpenSUSE Security Update for libmysofa (openSUSE-SU-2021:0444-1)