CVE-2020-28951

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
19/11/2020
Last modified:
07/11/2023

Description

libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package names. This is related to uci_parse_package in file.c and uci_strdup in util.c.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:openwrt:openwrt:*:*:*:*:*:*:*:* 18.06.9 (excluding)
cpe:2.3:o:openwrt:openwrt:*:*:*:*:*:*:*:* 19.07.0 (including) 19.07.5 (excluding)