CVE-2020-36152: Buffer Overflow
Published Feb 8, 2021
·Updated
Buffer overflow in readDataVar in hdf/dataobject.c in Symonics libmysofa 0.5 - 1.1 allows attackers to execute arbitrary code via a crafted SOFA.
Affected Software
2 affected components
Symonics libmysofa>=0.5<=1.1
Fedoraproject Fedora=32
Remediation
Patch Available
Event History
Feb 8, 2021
CVE Published
via MITRE·08:13 PM
Data Sourced
via MITRE·08:13 PM
Description
Frequently Asked Questions
1
What is CVE-2020-36152?
CVE-2020-36152 is a buffer overflow vulnerability in Symonics libmysofa version 0.5 - 1.1.
2
How does CVE-2020-36152 work?
CVE-2020-36152 can be exploited by attackers to execute arbitrary code by crafting a specially crafted SOFA file.
3
Which software versions are affected by CVE-2020-36152?
Symonics libmysofa versions 0.5 to 1.1 and Fedora version 32 are affected by CVE-2020-36152.
4
What is the severity of CVE-2020-36152?
CVE-2020-36152 has a severity rating of 8.8, which is considered high.
5
How can CVE-2020-36152 be fixed?
To fix CVE-2020-36152, users should update to a patched version of Symonics libmysofa or apply the necessary security updates for Fedora 32.