Vulnerability Description
Google gperftools 2.7 has a memory leak in malloc_extension.cc, related to MallocExtension::Register and InitModule. NOTE: the software maintainer indicates that this is not a bug; it is only a false-positive report from the LeakSanitizer program
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gperftools Project | Gperftools | 2.7 |
Related Weaknesses (CWE)
References
- https://github.com/gperftools/gperftools/issues/1013Third Party Advisory
- https://github.com/gperftools/gperftools/issues/1013Third Party Advisory
FAQ
What is CVE-2018-13420?
CVE-2018-13420 is a vulnerability with a CVSS score of 7.5 (HIGH). Google gperftools 2.7 has a memory leak in malloc_extension.cc, related to MallocExtension::Register and InitModule. NOTE: the software maintainer indicates that this is not a bug; it is only a false-...
How severe is CVE-2018-13420?
CVE-2018-13420 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-13420?
Check the references section above for vendor advisories and patch information. Affected products include: Gperftools Project Gperftools.