CVE-2020-28928 log

Source
Severity Medium
Remote No
Type Arbitrary code execution
Description
The wcsnrtombs function in all musl libc versions up to 1.2.1 has been found to have multiple bugs in the handling of the destination buffer size when limiting the input character count, which can lead to an infinite loop with no progress (no overflow) or to writing past the end of the destination buffer.
Group Package Affected Fixed Severity Status Ticket
AVG-1287 musl 1.2.1-1 1.2.1-2 Medium Fixed FS#68685
Date Advisory Group Package Severity Type
26 Nov 2020 ASA-202011-29 AVG-1287 musl Medium arbitrary code execution
References
https://www.openwall.com/lists/musl/2020/11/19/1
https://git.musl-libc.org/cgit/musl/commit/?id=3ab2a4e02682df1382955071919d8aa3c3ec40d4