CVE-2020-15476: High severity ndpi vulnerability
In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpisearchoracle in lib/protocols/oracle.c.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-15476?
CVE-2020-15476 is a vulnerability in nDPI version up to 3.2 that allows a heap-based buffer over-read in the Oracle protocol dissector.
How severe is CVE-2020-15476?
CVE-2020-15476 is considered high severity with a CVSS score of 7.5.
Which software versions are affected by CVE-2020-15476?
Versions up to 3.2 of nDPI are affected by CVE-2020-15476.
How can I fix CVE-2020-15476?
To fix CVE-2020-15476, it is recommended to update nDPI to the latest version.
Where can I find more information about CVE-2020-15476?
You can find more information about CVE-2020-15476 in the references provided: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=21780, https://github.com/ntop/nDPI/commit/b69177be2fbe01c2442239a61832c44e40136c05, https://lists.debian.org/debian-lts-announce/2020/08/msg00052.html