CVE-2020-11937

EUVD-2020-4274
In whoopsie, parse_report() from whoopsie.c allows a local attacker to cause a denial of service via a crafted file. The DoS is caused by resource exhaustion due to a memory leak. Fixed in 0.2.52.5ubuntu0.5, 0.2.62ubuntu0.5 and 0.2.69ubuntu0.1.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
canonicalCNA
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 23%
Affected Products (NVD)
VendorProductVersion
canonicalwhoopsie
0.2.66
canonicalwhoopsie
0.2.67
canonicalwhoopsie
0.2.68
canonicalwhoopsie
0.2.69
canonicalwhoopsie
0.2.49
canonicalwhoopsie
0.2.50
canonicalwhoopsie
0.2.51
canonicalwhoopsie
0.2.52
canonicalwhoopsie
0.2.52.1
canonicalwhoopsie
0.2.52.2
canonicalwhoopsie
0.2.52.3
canonicalwhoopsie
0.2.52.4
canonicalwhoopsie
0.2.52.5
canonicalwhoopsie
0.2.52.5ubuntu0.1:ubuntu0.1
canonicalwhoopsie
0.2.52.5ubuntu0.2:ubuntu0.2
canonicalwhoopsie
0.2.52.5ubuntu0.3:ubuntu0.3
canonicalwhoopsie
0.2.52.5ubuntu0.4:ubuntu0.4
canonicalwhoopsie
0.2.58
canonicalwhoopsie
0.2.59
canonicalwhoopsie
0.2.59build1:build1
canonicalwhoopsie
0.2.60
canonicalwhoopsie
0.2.61
canonicalwhoopsie
0.2.62
canonicalwhoopsie
0.2.62ubuntu0.1:ubuntu0.1
canonicalwhoopsie
0.2.62ubuntu0.2:ubuntu0.2
canonicalwhoopsie
0.2.62ubuntu0.3:ubuntu0.3
canonicalwhoopsie
0.2.62ubuntu0.4:ubuntu0.4
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
whoopsie
bionic
Fixed 0.2.62ubuntu0.5
released
eoan
ignored
focal
Fixed 0.2.69ubuntu0.1
released
trusty
dne
xenial
Fixed 0.2.52.5ubuntu0.5
released