CVE-2020-11937Uncontrolled Resource Consumption in Whoopsie

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 76.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 6
Latest updateMay 24

Description

In whoopsie, parse_report() from whoopsie.c allows a local attacker to cause a denial of service via a crafted file. The DoS is caused by resource exhaustion due to a memory leak. Fixed in 0.2.52.5ubuntu0.5, 0.2.62ubuntu0.5 and 0.2.69ubuntu0.1.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

CVEListV5canonical/whoopsie0.2.520.2.52.5ubuntu0.5+2
Ubuntuwhoopsie_project/whoopsie< 0.2.52.5ubuntu0.5+2
NVDcanonical/whoopsie27 versions+26

🔴Vulnerability Details

4
GHSA
GHSA-fcfw-r6pj-x447: In whoopsie, parse_report() from whoopsie2022-05-24
CVEList
Resource exhaustion vulnerability in whoopsie2020-08-06
OSV
whoopsie vulnerabilities2020-08-04
OSV
CVE-2020-11937: In whoopsie, parse_report() from whoopsie2020-06-11

📋Vendor Advisories

1
Ubuntu
Whoopsie vulnerabilities2020-08-04
CVE-2020-11937 — Uncontrolled Resource Consumption | cvebase