Heap Overflow Vulnerability in Retdec Product by Avast
CVE-2020-23907

9.8CRITICAL

Key Information:

Vendor

Avast

Status
Vendor
CVE Published:
21 April 2021

What is CVE-2020-23907?

A vulnerability in the Retdec v3.3 software can lead to an out-of-bounds read due to a heap buffer overflow. This issue arises from improper handling in the canSplitFunctionOn() function located within ir_modifications.cpp. The resulting effects can include denial of service, unauthorized memory disclosure, and possibly enable malicious code execution. Users of Retdec should take immediate action to mitigate potential risks related to this vulnerability.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.