CVE-2020-36401 - log back

CVE-2020-36401 edited at 01 Jul 2021 09:24:47
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Arbitrary code execution
Description
+ mruby 2.1.2 has a double free in mrb_default_allocf (called from mrb_free and obj_free).
References
+ https://github.com/google/oss-fuzz-vulns/blob/main/vulns/mruby/OSV-2020-744.yaml
+ https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=23801
+ https://github.com/mruby/mruby/commit/97319697c8f9f6ff27b32589947e1918e3015503
Notes
CVE-2020-36401 created at 01 Jul 2021 09:23:41