CVE-2020-28928
published 2020-11-24CVE-2020-28928: In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source character limit, as demonstrated by an invalid…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.64%
46.8th percentile
In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source character limit, as demonstrated by an invalid write access (buffer overflow).
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | musl | < musl 1.2.2-1 (bookworm) | musl 1.2.2-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| musl-libc | musl | <= 1.2.1 | — |
| musl-libc | musl | >= 0 < 1.2.2-1 | 1.2.2-1 |
| musl-libc | musl | >= 0 < 1.2.2-1 | 1.2.2-1 |
| musl-libc | musl | >= 0 < 1.2.2-1 | 1.2.2-1 |
| musl-libc | musl | >= 0 < 1.2.2-1 | 1.2.2-1 |
| musl-libc | musl | >= 0 < 0.9.15-1ubuntu0.1~esm2 | 0.9.15-1ubuntu0.1~esm2 |
| musl-libc | musl | >= 0 < 1.1.9-1ubuntu0.1~esm3 | 1.1.9-1ubuntu0.1~esm3 |
| musl-libc | musl | >= 0 < 1.1.19-1ubuntu0.1~esm1 | 1.1.19-1ubuntu0.1~esm1 |
| musl-libc | musl | >= 0 < 1.1.24-1ubuntu0.1~esm1 | 1.1.24-1ubuntu0.1~esm1 |
| oracle | graalvm | — | — |
| oracle | graalvm | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian5.5MEDIUM
vendor_oracle5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
musl vulnerabilities
osv·2023-03-31·CVSS 9.8
CVE-2019-14697 [CRITICAL] musl vulnerabilities
musl vulnerabilities
It was discovered that musl did not handle certain i386 math functions
properly. An attacker could use this vulnerability to cause a denial of
service (crash) or possibly execute arbitrary code. This issue only
affected Ubuntu 14.04 ESM, Ubuntu 16.04 ESM, and Ubuntu 18.04 LTS.
(CVE-2019-14697)
It was discovered that musl did not handle wide-character conversion
properly. A remote attacker could use this vulnerability to cause resource
consumption (infinite loop), denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 14.04 ESM, Ubuntu 16.04
ESM, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2020-28928)
GHSA
GHSA-7gwx-j9qc-6c6w: In musl libc through 1
ghsa_unreviewed·2022-05-24
CVE-2020-28928 [MEDIUM] CWE-787 GHSA-7gwx-j9qc-6c6w: In musl libc through 1
In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source character limit, as demonstrated by an invalid write access (buffer overflow).
OSV
CVE-2020-28928: In musl libc through 1
osv·2020-11-24·CVSS 5.5
CVE-2020-28928 [MEDIUM] CVE-2020-28928: In musl libc through 1
In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source character limit, as demonstrated by an invalid write access (buffer overflow).
Ubuntu
musl vulnerabilities
vendor_ubuntu·2023-03-31·CVSS 9.8
CVE-2020-28928 [CRITICAL] musl vulnerabilities
Title: musl vulnerabilities
Summary: Several security issues were fixed in musl.
It was discovered that musl did not handle certain i386 math functions
properly. An attacker could use this vulnerability to cause a denial of
service (crash) or possibly execute arbitrary code. This issue only
affected Ubuntu 14.04 ESM, Ubuntu 16.04 ESM, and Ubuntu 18.04 LTS.
(CVE-2019-14697)
It was discovered that musl did not handle wide-character conversion
properly. A remote attacker could use this vulnerability to cause resource
consumption (infinite loop), denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 14.04 ESM, Ubuntu 16.04
ESM, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2020-28928)
Instructions: In general, a standard system update will make all the neces
Oracle
Oracle Oracle Java SE Risk Matrix: LLVM Interpreter (musl libc) — CVE-2020-28928
vendor_oracle·2021-07-15·CVSS 5.5
CVE-2020-28928 [MEDIUM] Oracle Oracle Java SE Risk Matrix: LLVM Interpreter (musl libc) — CVE-2020-28928
Oracle Oracle Java SE Risk Matrix: LLVM Interpreter (musl libc) vulnerability
CVE: CVE-2020-28928
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2021 (JUL 2021)
Debian
CVE-2020-28928: musl - In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of des...
vendor_debian·2020·CVSS 5.5
CVE-2020-28928 [MEDIUM] CVE-2020-28928: musl - In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of des...
In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source character limit, as demonstrated by an invalid write access (buffer overflow).
Scope: local
bookworm: resolved (fixed in 1.2.2-1)
bullseye: resolved (fixed in 1.2.2-1)
forky: resolved (fixed in 1.2.2-1)
sid: resolved (fixed in 1.2.2-1)
trixie: resolved (fixed in 1.2.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2020/11/20/4https://lists.apache.org/thread.html/r2134abfe847bea7795f0e53756d10a47e6643f35ab8169df8b8a9eb1%40%3Cnotifications.apisix.apache.org%3Ehttps://lists.apache.org/thread.html/r90b60cf49348e515257b4950900c1bd3ab95a960cf2469d919c7264e%40%3Cnotifications.apisix.apache.org%3Ehttps://lists.apache.org/thread.html/ra63e8dc5137d952afc55dbbfa63be83304ecf842d1eab1ff3ebb29e2%40%3Cnotifications.apisix.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/11/msg00050.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKQ3RVSMVZNZNO4D65W2CZZ4DMYFZN2Q/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UW27QVY7ERPTSGKS4KAWE5TU7EJWHKVQ/https://musl.libc.org/releases.htmlhttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttp://www.openwall.com/lists/oss-security/2020/11/20/4https://lists.apache.org/thread.html/r2134abfe847bea7795f0e53756d10a47e6643f35ab8169df8b8a9eb1%40%3Cnotifications.apisix.apache.org%3Ehttps://lists.apache.org/thread.html/r90b60cf49348e515257b4950900c1bd3ab95a960cf2469d919c7264e%40%3Cnotifications.apisix.apache.org%3Ehttps://lists.apache.org/thread.html/ra63e8dc5137d952afc55dbbfa63be83304ecf842d1eab1ff3ebb29e2%40%3Cnotifications.apisix.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/11/msg00050.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKQ3RVSMVZNZNO4D65W2CZZ4DMYFZN2Q/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UW27QVY7ERPTSGKS4KAWE5TU7EJWHKVQ/https://musl.libc.org/releases.htmlhttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2020-11-24
Published