CVE-2019-14872

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
19/03/2020
Last modified:
24/03/2020

Description

The _dtoa_r function of the newlib libc library, prior to version 3.3.0, performs multiple memory allocations without checking their return value. This could result in NULL pointer dereference.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:newlib_project:newlib:*:*:*:*:*:*:*:* 3.3.0 (excluding)