CVE-2020-11940: GHSL-2020-051, GHSL-2020-052: Multiple vulnerabilities in NTOP nDPI
In nDPI through 3.2 Stable, an out-of-bounds read in concathashstring in ssh.c can be exploited by a network-positioned attacker that can send malformed SSH protocol messages on a network segment monitored by nDPI's library.
Other sources
The NTOP Deep Packet Inspection Toolkit is driven in large part by the nDPI library. This library contains a large set of network protocol dissectors intended to parse and analyze packet-captured network traffic.
— GitHub Security Lab
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-11940?
CVE-2020-11940 is classified as a medium-severity vulnerability due to the potential for exploitation by attackers.
How do I fix CVE-2020-11940?
To fix CVE-2020-11940, upgrade nDPI to version 3.3 or later, which addresses this vulnerability.
What impact does CVE-2020-11940 have on nDPI?
CVE-2020-11940 allows an attacker to exploit out-of-bounds reads in nDPI's handling of malformed SSH messages.
Who is affected by CVE-2020-11940?
Any service or application using nDPI versions up to 3.2 is vulnerable to CVE-2020-11940.
Can CVE-2020-11940 be exploited remotely?
Yes, CVE-2020-11940 can be exploited by remote attackers positioned on the same network segment.