Vulnerability Details CVE-2020-28951
libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package names. This is related to uci_parse_package in file.c and uci_strdup in util.c.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 65.7%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 10.0
Products affected by CVE-2020-28951
-
cpe:2.3:o:openwrt:openwrt:-
-
cpe:2.3:o:openwrt:openwrt:15.05.1
-
cpe:2.3:o:openwrt:openwrt:17.01.0
-
cpe:2.3:o:openwrt:openwrt:17.01.1
-
cpe:2.3:o:openwrt:openwrt:17.01.2
-
cpe:2.3:o:openwrt:openwrt:17.01.3
-
cpe:2.3:o:openwrt:openwrt:17.01.4
-
cpe:2.3:o:openwrt:openwrt:17.01.5
-
cpe:2.3:o:openwrt:openwrt:17.01.6
-
cpe:2.3:o:openwrt:openwrt:17.01.7
-
cpe:2.3:o:openwrt:openwrt:18.06.0
-
cpe:2.3:o:openwrt:openwrt:18.06.1
-
cpe:2.3:o:openwrt:openwrt:18.06.2
-
cpe:2.3:o:openwrt:openwrt:18.06.3
-
cpe:2.3:o:openwrt:openwrt:18.06.4
-
cpe:2.3:o:openwrt:openwrt:18.06.5
-
cpe:2.3:o:openwrt:openwrt:18.06.6
-
cpe:2.3:o:openwrt:openwrt:18.06.7
-
cpe:2.3:o:openwrt:openwrt:18.06.8
-
cpe:2.3:o:openwrt:openwrt:19.07.0
-
cpe:2.3:o:openwrt:openwrt:19.07.1
-
cpe:2.3:o:openwrt:openwrt:19.07.2
-
cpe:2.3:o:openwrt:openwrt:19.07.3
-
cpe:2.3:o:openwrt:openwrt:19.07.4