Vulnerability Description
U.S. Air Force Sensor Data Management System extract75 has a buffer overflow that leads to code execution. An overflow in a global variable (sBuffer) leads to a Write-What-Where outcome. Writing beyond sBuffer will clobber most global variables until reaching a pointer such as DES_info or image_info. By controlling that pointer, one achieves an arbitrary write when its fields are assigned. The data written is from a potentially untrusted NITF file in the form of an integer. The attacker can gain control of the instruction pointer.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Airforce | Nitf Extract Utility | 7.5 |
Related Weaknesses (CWE)
References
- https://www.riverloopsecurity.com/blog/2020/09/nitf-extract75-cve-2020-13995/ExploitThird Party Advisory
- https://www.riverloopsecurity.com/blog/2020/09/nitf-extract75-cve-2020-13995/ExploitThird Party Advisory
FAQ
What is CVE-2020-13995?
CVE-2020-13995 is a vulnerability with a CVSS score of 9.8 (CRITICAL). U.S. Air Force Sensor Data Management System extract75 has a buffer overflow that leads to code execution. An overflow in a global variable (sBuffer) leads to a Write-What-Where outcome. Writing beyon...
How severe is CVE-2020-13995?
CVE-2020-13995 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-13995?
Check the references section above for vendor advisories and patch information. Affected products include: Airforce Nitf Extract Utility.