CVE-2020-11939: GHSL-2020-051, GHSL-2020-052: Multiple vulnerabilities in NTOP nDPI
In nDPI through 3.2 Stable, the SSH protocol dissector has multiple KEXINIT integer overflows that result in a controlled remote heap overflow in concathashstring in ssh.c. Due to the granular nature of the overflow primitive and the ability to control both the contents and layout of the nDPI library's heap memory through remote input, this vulnerability may be abused to achieve full Remote Code Execution against any network inspection stack that is linked against nDPI and uses it to perform network traffic analysis.
Other sources
The NTOP Deep Packet Inspection Toolkit is driven in large part by the nDPI library. This library contains a large set of network protocol dissectors intended to parse and analyze packet-captured network traffic.
— GitHub Security Lab
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-11939?
CVE-2020-11939 has a medium severity score due to the potential for controlled remote memory corruption.
How do I fix CVE-2020-11939?
To remediate CVE-2020-11939, update nDPI to version 3.2 or later.
What impact does CVE-2020-11939 have on nDPI users?
CVE-2020-11939 can lead to remote code execution if exploited through SSH KEXINIT integer overflows.
Which versions of nDPI are affected by CVE-2020-11939?
CVE-2020-11939 affects all versions of nDPI up to and including 3.2.
Who is the vendor for CVE-2020-11939?
The vendor for CVE-2020-11939 is ntop, the maintainers of nDPI.