7.8
CVE-2020-20740
- EPSS 1.06%
- Veröffentlicht 20.11.2020 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:12:15
- Erkennungen
PDFResurrect before 0.20 lack of header validation checks causes heap-buffer-overflow in pdf_get_version().
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pdfresurrect Project ≫ Pdfresurrect Version < 0.20
Debian ≫ Debian Linux Version 9.0
Fedoraproject ≫ Fedora Version 32
Fedoraproject ≫ Fedora Version 33
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.06% | 0.617 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| NIST | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
https://lists.debian.org/debian-lts-announce/2020/12/msg00002.html
https://github.com/enferex/pdfresurrect/commit/1b422459f07353adce2878806d5247d9e91fb397
https://github.com/enferex/pdfresurrect/issues/14
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMEEEPBBGER5LPABBRVZLMCC6Z24RBXW/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZOIEVFM3SIMAEOFJKKMYH2TLZ7PXLSUD/