VDB

CVE-2020-19725

CVE-2020-19725 PUBLISHED CVSS 7.800000190734863 HIGH

There is a use-after-free vulnerability in file pdd_simplifier.cpp in Z3 before 4.8.8. It occurs when the solver attempt to simplify the constraints and causes unexpected memory access. It can cause segmentation faults or arbitrary code execution.

EPSS 1.03% · 61.5th percentile

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
1.03%
61.5th percentile

Affected Products

VendorProductVersions
Ubuntu:24.04:LTSz34.8.12-3.1, 0, 4.8.12-3.1build1
Ubuntu:20.04:LTSz34.8.7-4build1, 0, 4.8.4-1build1
Ubuntu:18.04:LTSz34.4.1-0.3build4, 4.4.1-0.3build3, 0
Ubuntu:25.10z30, 4.13.3-1
Ubuntu:16.04:LTSz34.4.0-3, 4.4.0-2, 4.4.0-3build1
Ubuntu:22.04:LTSz30, 4.8.12-1

Timeline

  • Aug 22, 2023 CVE Published
  • Aug 23, 2023 EPSS Score
  • Sep 25, 2023 EPSS Score
  • Oct 29, 2023 EPSS Score
  • Dec 1, 2023 EPSS Score
  • Jan 3, 2024 EPSS Score
  • Feb 6, 2024 EPSS Score
  • Mar 10, 2024 EPSS Score
  • Apr 12, 2024 EPSS Score
  • Jun 18, 2024 EPSS Score
  • Jul 21, 2024 EPSS Score
  • Aug 24, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›