First published: Mon Sep 09 2019(Updated: )
GNU cflow through 1.6 has a use-after-free in the reference function in parser.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU cflow | <=1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2019-16165.
The severity of CVE-2019-16165 is medium with a severity value of 6.5.
The affected software by CVE-2019-16165 is GNU cflow 1.6 or earlier.
CVE-2019-16165 is a vulnerability in GNU cflow 1.6 that allows a use-after-free condition in the reference function in parser.c.
Yes, you can find more information about CVE-2019-16165 at this link: [https://lists.gnu.org/archive/html/bug-cflow/2019-04/msg00001.html](https://lists.gnu.org/archive/html/bug-cflow/2019-04/msg00001.html).