First published: Wed Apr 21 2021(Updated: )
An issue was discovered in retdec v3.3. In function canSplitFunctionOn() of ir_modifications.cpp, there is a possible out of bounds read due to a heap buffer overflow. The impact is: Deny of Service, Memory Disclosure, and Possible Code Execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Avast Retdec | =3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-23907 is critical with a CVSS score of 9.8.
CVE-2020-23907 can be exploited through a heap buffer overflow, leading to possible code execution, memory disclosure, and denial of service.
The affected software version is Avast Retdec 3.3.
Yes, a fix for CVE-2020-23907 is available. Please refer to the provided references for more information on the fix.
CVE-2020-23907 is associated with CWE-119 (Improper restriction of operations within the bounds of a memory buffer) and CWE-787 (Out-of-bounds Write).