First published: Mon Jan 13 2020(Updated: )
libmysofa 0.9.1 has a stack-based buffer overflow in readDataVar in hdf/dataobject.c during the reading of a header message attribute.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symonics libmysofa | =0.9.1 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6860 is a vulnerability in libmysofa 0.9.1 that allows for a stack-based buffer overflow during the reading of a header message attribute.
CVE-2020-6860 has a severity rating of 8.8 (high).
CVE-2020-6860 affects libmysofa 0.9.1, Fedora 34, and Fedora 35.
To fix CVE-2020-6860, it is recommended to update libmysofa to a version that addresses the vulnerability.
Yes, references for CVE-2020-6860 can be found at the following links: [Link 1](https://github.com/hoene/libmysofa/issues/96), [Link 2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PGQ45S4RH7MC42NHTAGOIHYR4C5IRTMZ/), [Link 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WGY7TAZX2M4NYXXGNHIBBKKN5XMSMKQ4/)