Lucene search

K
cvelistRedhatCVELIST:CVE-2021-20204
HistoryMay 06, 2021 - 2:50 p.m.

CVE-2021-20204

2021-05-0614:50:52
CWE-119
redhat
www.cve.org
7
cve-2021-20204
memory corruption
libgetdata

AI Score

10

Confidence

High

EPSS

0.011

Percentile

84.8%

A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This degrades the confidentiality, integrity and availability of third-party software that uses libgetdata as a library. This vulnerability may lead to arbitrary code execution or privilege escalation depending on input/skills of attacker.

CNA Affected

[
  {
    "product": "getdata",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "v0.10.0"
      }
    ]
  }
]

AI Score

10

Confidence

High

EPSS

0.011

Percentile

84.8%