← Back

CVE-2020-11937

nvd nist
Published: Aug 6, 2020Modified: Nov 21, 2024

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

In whoopsie, parse_report() from whoopsie.c allows a local attacker to cause a denial of service via a crafted file. The DoS is caused by resource exhaustion due to a memory leak. Fixed in 0.2.52.5ubuntu0.5, 0.2.62ubuntu0.5 and 0.2.69ubuntu0.1.

Affected (27)

Products: Canonical: Whoopsie
1 product
Whoopsie
Configuration A
4 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Canonical
Version 0.2.66
Version 0.2.67
Version 0.2.68
Version 0.2.69
Running on/withPlatform Versions
Canonical
Ubuntu Linux
Version 20.04
Configuration B
13 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Canonical
Version 0.2.49
Version 0.2.50
Version 0.2.51
Version 0.2.52.1
Version 0.2.52.2
Version 0.2.52.3
Version 0.2.52.4
Version 0.2.52.5
Version 0.2.52.5ubuntu0.1
Version 0.2.52.5ubuntu0.2
Version 0.2.52.5ubuntu0.3
Version 0.2.52.5ubuntu0.4
Version 0.2.52
Running on/withPlatform Versions
Canonical
Ubuntu Linux
Version 16.04
Configuration C
10 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Canonical
Version 0.2.58
Version 0.2.59
Version 0.2.59build1
Version 0.2.60
Version 0.2.61
Version 0.2.62
Version 0.2.62ubuntu0.1
Version 0.2.62ubuntu0.2
Version 0.2.62ubuntu0.3
Version 0.2.62ubuntu0.4
Running on/withPlatform Versions
Canonical
Ubuntu Linux
Version 18.04

References (8)

Source: security@ubuntu.com
ExploitThird Party Advisory
Source: security@ubuntu.com
ExploitIssue TrackingThird Party Advisory
Source: security@ubuntu.com
Vendor Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.