CVE-2019-20503Out-of-bounds Read in Project Usrsctp

CWE-125Out-of-bounds Read19 documents12 sources
Severity
6.5MEDIUMNVD
OSV8.8
EPSS
2.5%
top 14.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 6
Latest updateMay 24

Description

usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

Ubuntumozilla/firefox< 74.0+build3-0ubuntu0.16.04.1+1
Debianchromium/chromium< 80.0.3987.149-1+3
Debianmozilla/thunderbird< 1:68.6.0-1+3
Ubuntumozilla/thunderbird< 1:68.7.0+build1-0ubuntu0.16.04.2+1

Also affects: Debian Linux 10.0, 8.0, 9.0, Ubuntu Linux 16.04, 18.04, 19.10

Patches

🔴Vulnerability Details

6
GHSA
GHSA-48ww-7497-cmhw: usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init2022-05-24
OSV
thunderbird vulnerabilities2020-04-21
OSV
thunderbird vulnerabilities2020-04-13
OSV
firefox vulnerabilities2020-03-11
CVEList
CVE-2019-20503: usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init2020-03-06

💥Exploits & PoCs

1
Exploit-DB
SirsiDynix e-Library 3.5.x - Cross-Site Scripting2019-01-24

📋Vendor Advisories

10
Ubuntu
Thunderbird vulnerabilities2020-04-21
Ubuntu
Thunderbird vulnerabilities2020-04-13
Chrome
Stable Channel Update for Desktop: CVE-2020-64292020-03-18
Ubuntu
Firefox vulnerabilities2020-03-11
Microsoft
usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.2020-03-10

💬Community

1
Bugzilla
CVE-2019-20503 usrsctp: Out of bounds reads in sctp_load_addresses_from_init()2020-03-10
CVE-2019-20503 — Out-of-bounds Read in Project Usrsctp | cvebase