VDB

CVE-2020-18897

CVE-2020-18897 PUBLISHED

An use-after-free vulnerability in the libpff_item_tree_create_node function of libyal Libpff before 20180623 allows attackers to cause a denial of service (DOS) or execute arbitrary code via a crafted pff file.

EPSS 0.10% · 28.1th percentile

Risk Scores

EPSS Score
0.10%
28.1th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlibpff20120802-5, 20120802-5.1, 0
Ubuntu:16.04:LTSlibpff20120802-5, 0

Timeline

  • Aug 19, 2021 CVE Published
  • Aug 20, 2021 EPSS Score
  • Oct 17, 2021 EPSS Score
  • Dec 15, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 11, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Apr 11, 2022 EPSS Score
  • Jun 8, 2022 EPSS Score
  • Aug 6, 2022 EPSS Score
  • Oct 4, 2022 EPSS Score
  • Dec 1, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›