VDB
CVE-2020-23856
CVE-2020-23856
PUBLISHED
Use-after-Free vulnerability in cflow 1.6 in the void call(char *name, int line) function at src/parser.c, which could cause a denial of service via the pointer variable caller->callee.
EPSS 0.14% · 34.0th percentile
Risk Scores
EPSS Score
0.14%
34.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:20.04:LTS | cflow | 0, 1:1.6-4 |
| Ubuntu:25.10 | cflow | 1:1.7-5, 0, 1:1.8-1 |
| Ubuntu:Pro:16.04:LTS | cflow | 1:1.4+dfsg1-3ubuntu1.16.04.1~esm1, 1:1.4+dfsg1-3ubuntu1, 0 |
| Ubuntu:22.04:LTS | cflow | 1:1.6-4, 1:1.7-2, * |
| Ubuntu:Pro:18.04:LTS | cflow | 1:1.4+dfsg1-3ubuntu1.18.04.1~esm1, 0, 1:1.4+dfsg1-3ubuntu1 |
| Ubuntu:24.04:LTS | cflow | 1:1.7-5, 1:1.7-4, 0 |
Exploit Intelligence
Timeline
- May 18, 2021 CVE Published
- May 19, 2021 EPSS Score
- Jun 1, 2021 EPSS Score
- Jul 22, 2021 EPSS Score
- Nov 22, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Jan 22, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 25, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Jul 27, 2022 EPSS Score
- Sep 26, 2022 EPSS Score
References
- https://ubuntu.com/security/CVE-2020-23856 third-party-advisory
- https://lists.gnu.org/archive/html/bug-cflow/2020-07/msg00000.html third-party-advisory
- https://github.com/yangjiageng/PoC/blob/master/PoC_cflow_uaf_parser_line1284 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2020-23856 third-party-advisory