CRITICAL · 9.8

CVE-2021-20204

A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This degrades the confidentiality, integrity and availab...

Vulnerability Description

A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This degrades the confidentiality, integrity and availability of third-party software that uses libgetdata as a library. This vulnerability may lead to arbitrary code execution or privilege escalation depending on input/skills of attacker.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Getdata ProjectGetdata0.10.0
DebianDebian Linux9.0
FedoraprojectFedora33

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-20204?

CVE-2021-20204 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This degrades the confidentiality, integrity and availab...

How severe is CVE-2021-20204?

CVE-2021-20204 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2021-20204?

Check the references section above for vendor advisories and patch information. Affected products include: Getdata Project Getdata, Debian Debian Linux, Fedoraproject Fedora.