CVE-2020-23907: Buffer Overflow
An issue was discovered in retdec v3.3. In function canSplitFunctionOn() of irmodifications.cpp, there is a possible out of bounds read due to a heap buffer overflow. The impact is: Deny of Service, Memory Disclosure, and Possible Code Execution.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-23907?
The severity of CVE-2020-23907 is critical with a CVSS score of 9.8.
How can CVE-2020-23907 be exploited?
CVE-2020-23907 can be exploited through a heap buffer overflow, leading to possible code execution, memory disclosure, and denial of service.
Which software versions are affected by CVE-2020-23907?
The affected software version is Avast Retdec 3.3.
Is there a fix available for CVE-2020-23907?
Yes, a fix for CVE-2020-23907 is available. Please refer to the provided references for more information on the fix.
What is the Common Weakness Enumeration (CWE) associated with CVE-2020-23907?
CVE-2020-23907 is associated with CWE-119 (Improper restriction of operations within the bounds of a memory buffer) and CWE-787 (Out-of-bounds Write).