CVE-2020-6860Out-of-bounds Write in Libmysofa

Severity
8.8HIGHNVD
EPSS
0.5%
top 32.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13
Latest updateMay 24

Description

libmysofa 0.9.1 has a stack-based buffer overflow in readDataVar in hdf/dataobject.c during the reading of a header message attribute.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

debiandebian/libmysofa< libmysofa 1.0~dfsg0-1 (bookworm)
Debiansymonics/libmysofa< 1.0~dfsg0-1+3

Also affects: Fedora 34, 35

🔴Vulnerability Details

2
GHSA
GHSA-5ccx-hhh5-cc4v: libmysofa 02022-05-24
OSV
CVE-2020-6860: libmysofa 02020-01-13

📋Vendor Advisories

1
Debian
CVE-2020-6860: libmysofa - libmysofa 0.9.1 has a stack-based buffer overflow in readDataVar in hdf/dataobje...2020
CVE-2020-6860 — Out-of-bounds Write in Debian Libmysofa | cvebase