CVE-2020-28951
19.11.2020, 19:15
libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package names. This is related to uci_parse_package in file.c and uci_strdup in util.c.Enginsight
Vendor | Product | Version |
---|---|---|
openwrt | openwrt | 𝑥 < 18.06.9 |
openwrt | openwrt | 19.07.0 ≤ 𝑥 < 19.07.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References