CVE-2019-20503

usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
VendorProductVersion
usrsctp_projectusrsctp
𝑥
< 0.9.4.0
debiandebian_linux
8.0
debiandebian_linux
9.0
debiandebian_linux
10.0
canonicalubuntu_linux
16.04
canonicalubuntu_linux
18.04
canonicalubuntu_linux
19.10
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
chromium
bullseye (security)
120.0.6099.224-1~deb11u1
fixed
bullseye
120.0.6099.224-1~deb11u1
fixed
bookworm
128.0.6613.84-1~deb12u1
fixed
bookworm (security)
130.0.6723.91-1~deb12u1
fixed
trixie
129.0.6668.89-1
fixed
sid
130.0.6723.91-2
fixed
firefox
sid
132.0.1-1
fixed
firefox-esr
bullseye
115.14.0esr-1~deb11u1
fixed
bullseye (security)
128.4.0esr-1~deb11u1
fixed
bookworm
115.14.0esr-1~deb12u1
fixed
bookworm (security)
128.4.0esr-1~deb12u1
fixed
trixie
128.3.1esr-2
fixed
sid
128.4.0esr-1
fixed
libusrsctp
bullseye
0.9.3.0+20201102-2
fixed
sid
0.9.5.0-2
fixed
trixie
0.9.5.0-2
fixed
bookworm
0.9.5.0-2
fixed
thunderbird
bullseye
1:115.12.0-1~deb11u1
fixed
bullseye (security)
1:128.4.0esr-1~deb11u1
fixed
bookworm
1:115.12.0-1~deb12u1
fixed
bookworm (security)
1:115.16.0esr-1~deb12u1
fixed
sid
1:128.4.0esr-1
fixed
trixie
1:128.4.0esr-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
chromium-browser
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
not-affected
jammy
not-affected
impish
not-affected
hirsute
not-affected
groovy
not-affected
focal
not-affected
eoan
not-affected
bionic
Fixed 80.0.3987.149-0ubuntu0.18.04.1
released
xenial
Fixed 80.0.3987.149-0ubuntu0.16.04.1
released
trusty
dne
firefox
noble
Fixed 74.0+build3-0ubuntu1
released
mantic
Fixed 74.0+build3-0ubuntu1
released
lunar
Fixed 74.0+build3-0ubuntu1
released
kinetic
Fixed 74.0+build3-0ubuntu1
released
jammy
Fixed 74.0+build3-0ubuntu1
released
impish
Fixed 74.0+build3-0ubuntu1
released
hirsute
Fixed 74.0+build3-0ubuntu1
released
groovy
Fixed 74.0+build3-0ubuntu1
released
focal
Fixed 74.0+build3-0ubuntu1
released
eoan
Fixed 74.0+build3-0ubuntu0.19.10.1
released
bionic
Fixed 74.0+build3-0ubuntu0.18.04.1
released
xenial
Fixed 74.0+build3-0ubuntu0.16.04.1
released
trusty
dne
libusrsctp
noble
needs-triage
mantic
ignored
lunar
ignored
kinetic
ignored
jammy
needs-triage
impish
ignored
hirsute
ignored
groovy
ignored
focal
needs-triage
eoan
ignored
bionic
dne
xenial
dne
trusty
dne
thunderbird
noble
Fixed 1:68.6.0+build2-0ubuntu1
released
mantic
Fixed 1:68.6.0+build2-0ubuntu1
released
lunar
Fixed 1:68.6.0+build2-0ubuntu1
released
kinetic
Fixed 1:68.6.0+build2-0ubuntu1
released
jammy
Fixed 1:68.6.0+build2-0ubuntu1
released
impish
Fixed 1:68.6.0+build2-0ubuntu1
released
hirsute
Fixed 1:68.6.0+build2-0ubuntu1
released
groovy
Fixed 1:68.6.0+build2-0ubuntu1
released
focal
Fixed 1:68.6.0+build2-0ubuntu1
released
eoan
Fixed 1:68.7.0+build1-0ubuntu0.19.10.1
released
bionic
Fixed 1:68.7.0+build1-0ubuntu0.18.04.1
released
xenial
Fixed 1:68.7.0+build1-0ubuntu0.16.04.2
released
trusty
dne
References