In nDPI through 3.2, ndpi_reset_packet_line_info in lib/ndpi_main.c omits certain reinitialization, leading to a use-after-free.
References
Link | Resource |
---|---|
https://github.com/ntop/nDPI/commit/6a9f5e4f7c3fd5ddab3e6727b071904d76773952 | Patch Vendor Advisory |
Configurations
Information
Published : 2020-07-01 04:15
Updated : 2020-07-06 12:45
NVD link : CVE-2020-15475
Mitre link : CVE-2020-15475
JSON object : View
CWE
CWE-416
Use After Free
Products Affected
ntop
- ndpi