Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2020-36406: oss-fuzz-vulns/OSV-2020-1695.yaml at main · google/oss-fuzz-vulns

** DISPUTED ** uWebSockets 18.11.0 and 18.12.0 has a stack-based buffer overflow in uWS::TopicTree::trimTree (called from uWS::TopicTree::unsubscribeAll). NOTE: the vendor’s position is that this is “a minor issue or not even an issue at all” because the developer of an application (that uses uWebSockets) should not be allowing the large number of triggered topics to accumulate.

CVE
#web#google#git

Permalink

Cannot retrieve contributors at this time

id: OSV-2020-1695

summary: Stack-buffer-overflow in uWS::TopicTree::trimTree

details: |

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=25381

Crash type: Stack-buffer-overflow WRITE 8

Crash state:

uWS::TopicTree::trimTree

uWS::TopicTree::unsubscribeAll

TopicTree.cpp

modified: ‘2021-06-21T06:56:26.554807Z’

published: ‘2020-09-04T00:00:08.299412Z’

references:

- type: REPORT

url: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=25381

affected:

- package:

name: uwebsockets

ecosystem: OSS-Fuzz

ranges:

- type: GIT

repo: https://github.com/uNetworking/uWebSockets.git

events:

- introduced: c2dbcf0c046d50a8b53a6c2d9b522c201f17a338

- fixed: 03fca626a95130ab80f86adada54b29d27242759

versions:

- v18.11.0

- v18.12.0

ecosystem_specific:

severity: HIGH

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907