CVE-2020-11937
MEDIUM 5.5EPSS 0.5%
In whoopsie, parse_report() from whoopsie.c allows a local attacker to cause a denial of service via a crafted file. The DoS is caused by resource exhaustion due to a memory leak. Fixed in 0.2.52.5ubuntu0.5, 0.2.62ubuntu0.5 and 0.2.69ubuntu0.1.
- CVSS v3.1
- 5.5 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H - CVSS v3.1
- 5.5 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H - CVSS v2.0
- 2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P - EPSS
- 0.47% chance of exploitation in the next 30 days, 39th percentile
- Published
- 2020-08-06
- Updated
- 2024-09-17
Proof-of-concept exploits (2)
- sungjungk/whoopsie_killer2★ · 2020-06-29
- https://launchpad.net/bugs/1881982