CVE-2020-28928
24.11.2020, 18:15
In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source character limit, as demonstrated by an invalid write access (buffer overflow).Enginsight
| Vendor | Product | Version |
|---|---|---|
| musl-libc | musl | 𝑥 ≤ 1.2.1 |
| debian | debian_linux | 9.0 |
| oracle | graalvm | 20.3.2 |
| oracle | graalvm | 21.1.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| musl |
|
Common Weakness Enumeration
References