In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demonstrated by a payload packet length that is too short.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-07-01T10:54:30
Updated: 2024-08-04T13:15:20.705Z
Reserved: 2020-07-01T00:00:00
Link: CVE-2020-15472
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-07-01T11:15:11.117
Modified: 2024-11-21T05:05:34.913
Link: CVE-2020-15472
Redhat
No data.