libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package names. This is related to uci_parse_package in file.c and uci_strdup in util.c.
2020-11-19T19:15:12.017
2024-11-21T05:23:22.047
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | openwrt | openwrt | < 18.06.9 | Yes |
Operating System | openwrt | openwrt | < 19.07.5 | Yes |