CVE-2020-36148: Null Pointer Dereference
Published Feb 8, 2021
·Updated
Incorrect handling of input data in verifyAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointer dereference and segmentation fault error in case of restrictive memory protection or near NULL pointer overwrite in case of no memory restrictions (e.g. in embedded environments).
Affected Software
2 affected components
Symonics libmysofa>=0.5<=1.1
Fedoraproject Fedora=32
Remediation
Event History
Feb 8, 2021
CVE Published
via MITRE·08:13 PM
Data Sourced
via MITRE·08:13 PM
Description
Frequently Asked Questions
1
What is CVE-2020-36148?
CVE-2020-36148 is a vulnerability that occurs due to incorrect handling of input data in the libmysofa library 0.5 - 1.1.
2
What is the severity of CVE-2020-36148?
The severity of CVE-2020-36148 is medium with a CVSS score of 6.5.
3
How does CVE-2020-36148 affect Symonics libmysofa?
Symonics libmysofa versions 0.5 to 1.1 are affected by CVE-2020-36148.
4
How does CVE-2020-36148 affect Fedora?
Fedora version 32 is affected by CVE-2020-36148.
5
How can I fix the CVE-2020-36148 vulnerability?
To fix the CVE-2020-36148 vulnerability, it is recommended to update the libmysofa library to a version above 1.1.