libubox in OpenWrt before 18.06.7 and 19.x before 19.07.1 has a tagged binary data JSON serialization vulnerability that may cause a stack based buffer overflow.
References
Link | Resource |
---|---|
https://github.com/openwrt/openwrt/commits/master | Patch Third Party Advisory |
https://nvd.nist.gov/vuln/detail/CVE-2020-7248#range-4512438 | Third Party Advisory US Government Resource |
https://openwrt.org/advisory/2020-01-31-2 | Vendor Advisory |
https://openwrt.org/advisory/2020-01-31-2 | Vendor Advisory |
https://github.com/openwrt/openwrt/commits/master | Patch Third Party Advisory |
https://nvd.nist.gov/vuln/detail/CVE-2020-7248#range-4512438 | Third Party Advisory US Government Resource |
https://openwrt.org/advisory/2020-01-31-2 | Vendor Advisory |
https://openwrt.org/advisory/2020-01-31-2 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:36
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/openwrt/openwrt/commits/master - Patch, Third Party Advisory | |
References | () https://nvd.nist.gov/vuln/detail/CVE-2020-7248#range-4512438 - Third Party Advisory, US Government Resource | |
References | () https://openwrt.org/advisory/2020-01-31-2 - Vendor Advisory |
24 May 2023, 15:01
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:openwrt:openwrt:19.07.0:rc1:*:*:*:*:*:* cpe:2.3:a:openwrt:openwrt:*:*:*:*:*:*:*:* cpe:2.3:a:openwrt:openwrt:19.07.0:rc2:*:*:*:*:*:* |
cpe:2.3:o:openwrt:openwrt:19.07.0:-:*:*:*:*:*:* cpe:2.3:o:openwrt:openwrt:19.07.0:rc1:*:*:*:*:*:* cpe:2.3:o:openwrt:openwrt:*:*:*:*:*:*:*:* cpe:2.3:o:openwrt:openwrt:19.07.0:rc2:*:*:*:*:*:* |
03 Sep 2022, 03:55
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://nvd.nist.gov/vuln/detail/CVE-2020-7248#range-4512438 - Third Party Advisory, US Government Resource |
09 May 2022, 17:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2020-03-16 21:15
Updated : 2024-11-21 05:36
NVD link : CVE-2020-7248
Mitre link : CVE-2020-7248
CVE.ORG link : CVE-2020-7248
JSON object : View
Products Affected
openwrt
- openwrt
CWE
CWE-787
Out-of-bounds Write