Vulnerabilities > CVE-2020-18897 - Use After Free vulnerability in Libpff Project Libpff 20161119/20180428

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
libpff-project
CWE-416

Summary

An use-after-free vulnerability in the libpff_item_tree_create_node function of libyal Libpff before 20180623 allows attackers to cause a denial of service (DOS) or execute arbitrary code via a crafted pff file.

Vulnerable Configurations

Part Description Count
Application
Libpff_Project
2

Common Weakness Enumeration (CWE)