Vulnerabilities > CVE-2020-18897 - Use After Free vulnerability in Libpff Project Libpff 20161119/20180428

047910
CVSS 4.4 - MEDIUM
Attack vector
LOCAL
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL

Summary

An use-after-free vulnerability in the libpff_item_tree_create_node function of libyal Libpff before 20180623 allows attackers to cause a denial of service (DOS) or execute arbitrary code via a crafted pff file.

Vulnerable Configurations

Part Description Count
Application
Libpff_Project
2

Common Weakness Enumeration (CWE)