CVE-2020-23856: Use After Free
Published May 18, 2021
·Updated
Use-after-Free vulnerability in cflow 1.6 in the void call(char name, int line) function at src/parser.c, which could cause a denial of service via the pointer variable caller->callee.
Affected Software
3 affected components
GNU cflow=1.6
fedoraproject fedora=33
fedoraproject fedora=34
Event History
May 18, 2021
CVE Published
via MITRE·02:41 PM
Data Sourced
via MITRE·02:41 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-23856?
The severity of CVE-2020-23856 is medium with a CVSS score of 5.5.
2
What is CVE-2020-23856?
CVE-2020-23856 is a use-after-free vulnerability in cflow 1.6 that can cause a denial of service.
3
How does CVE-2020-23856 affect cflow 1.6?
CVE-2020-23856 affects cflow 1.6 by exploiting a use-after-free vulnerability in the void call(char *name, int line) function at src/parser.c.
4
How can I fix CVE-2020-23856?
To fix CVE-2020-23856, update cflow to a version that has addressed the vulnerability.
5
Are there any references for CVE-2020-23856?
Yes, you can find references for CVE-2020-23856 at the following links: [LINKS]