In nDPI through 3.2, ndpi_reset_packet_line_info in lib/ndpi_main.c omits certain reinitialization, leading to a use-after-free.
References
Link | Resource |
---|---|
https://github.com/ntop/nDPI/commit/6a9f5e4f7c3fd5ddab3e6727b071904d76773952 | Patch Vendor Advisory |
https://github.com/ntop/nDPI/commit/6a9f5e4f7c3fd5ddab3e6727b071904d76773952 | Patch Vendor Advisory |
Configurations
History
21 Nov 2024, 05:05
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/ntop/nDPI/commit/6a9f5e4f7c3fd5ddab3e6727b071904d76773952 - Patch, Vendor Advisory |
Information
Published : 2020-07-01 11:15
Updated : 2024-11-21 05:05
NVD link : CVE-2020-15475
Mitre link : CVE-2020-15475
CVE.ORG link : CVE-2020-15475
JSON object : View
Products Affected
ntop
- ndpi
CWE
CWE-416
Use After Free