CVE-2020-6840: Use After Free
Published Jan 11, 2020
·Updated
In mruby 2.1.0, there is a use-after-free in hashslice in mrbgems/mruby-hash-ext/src/hash-ext.c.
Affected Software
1 affected component
mruby mruby=2.1.0
Remediation
Patch Available
Event History
Jan 11, 2020
CVE Published
via MITRE·02:05 AM
Data Sourced
via MITRE·02:05 AM
Description
Data Sourced
via NVD·03:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-6840.
2
What is the severity of CVE-2020-6840?
The severity of CVE-2020-6840 is critical with a CVSS score of 9.8.
3
What is the affected software version of CVE-2020-6840?
The affected software version of CVE-2020-6840 is mruby 2.1.0.
4
What is the description of CVE-2020-6840?
CVE-2020-6840 is a use-after-free vulnerability in hash_slice in mrbgems/mruby-hash-ext/src/hash-ext.c in mruby 2.1.0.
5
Is there a fix available for CVE-2020-6840?
Yes, a fix for CVE-2020-6840 is available. Please refer to the referenced link for more information.