CVE-2020-11937

In whoopsie, parse_report() from whoopsie.c allows a local attacker to cause a denial of service via a crafted file. The DoS is caused by resource exhaustion due to a memory leak. Fixed in 0.2.52.5ubuntu0.5, 0.2.62ubuntu0.5 and 0.2.69ubuntu0.1.
References
Link Resource
https://launchpad.net/bugs/1881982 Exploit Issue Tracking
https://github.com/sungjungk/whoopsie_killer Exploit Third Party Advisory
https://usn.ubuntu.com/4450-1 Vendor Advisory
https://usn.ubuntu.com/4450-1/ Third Party Advisory
Configurations

Configuration 1


Information

Published : 2020-08-06 11:15

Updated : 2021-09-13 02:27


NVD link : CVE-2020-11937

Mitre link : CVE-2020-11937

Products Affected
No products.
CWE