Description
The digest generation function of NHIServiSignAdapter has not been verified for parameter’s length, which leads to a stack overflow loophole. Remote attackers can use the leak to execute code without privilege.
No analysis available yet.
Remediation
Vendor Solution
Update to version 1.0.20.1109
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-18477 | The digest generation function of NHIServiSignAdapter has not been verified for parameter’s length, which leads to a stack overflow loophole. Remote attackers can use the leak to execute code without privilege. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-4272-23ba4-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T16:53:50.623Z
Reserved: 2020-09-23T00:00:00.000Z
Link: CVE-2020-25844
No data.
Status : Modified
Published: 2020-12-31T08:15:13.237
Modified: 2024-11-21T05:18:53.353
Link: CVE-2020-25844
No data.
OpenCVE Enrichment
No data.
EUVD