CVE-2020-36152 - log back

CVE-2020-36152 edited at 08 Feb 2021 23:05:24
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Local
Type
- Unknown
+ Arbitrary code execution
Description
+ A buffer overflow in readDataVar in hdf/dataobject.c in Symonics libmysofa 0.5 - 1.1 allows attackers to execute arbitrary code via a crafted SOFA.
References
+ https://github.com/hoene/libmysofa/issues/136
+ https://github.com/hoene/libmysofa/pull/146
+ https://github.com/hoene/libmysofa/pull/146/commits/d86f133dd871097b5e767da6742c109eb3a59886
Notes
CVE-2020-36152 created at 08 Feb 2021 22:56:11