CVE-2020-11958: Buffer Overflow
Published Apr 21, 2020
·Updated
Last updated 24 July 2024
Other sources
re2c 1.3 has a heap-based buffer overflow in Scanner::fill in parse/scanner.cc via a long lexeme.
Affected Software
4 affected componentsFixes available
debian/re2c
2.0.3-13.0-23.1-1
re2c re2c=1.3
Canonical Ubuntu Linux=19.10
Canonical Ubuntu Linux=20.04
Remediation
Event History
Apr 21, 2020
CVE Published
via MITRE·12:37 AM
Data Sourced
via MITRE·12:37 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:37 PM
Description
Sep 13, 2024
Data Sourced
via Ubuntu·12:00 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-11958?
CVE-2020-11958 is classified as a high-severity vulnerability due to its potential for remote exploitation via a heap-based buffer overflow.
2
How do I fix CVE-2020-11958?
To fix CVE-2020-11958, it is recommended to upgrade to re2c version 2.0.3-1 or later, depending on your package manager.
3
What software is affected by CVE-2020-11958?
CVE-2020-11958 affects re2c version 1.3, as well as specific versions of Debian and Ubuntu Linux distributions.
4
What type of vulnerability is CVE-2020-11958?
CVE-2020-11958 is a heap-based buffer overflow vulnerability that occurs in the Scanner::fill function.
5
Can CVE-2020-11958 be exploited remotely?
Yes, CVE-2020-11958 can potentially be exploited remotely due to the nature of the heap-based buffer overflow.