CVE-2020-28951
libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package nam
libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package names. This is related to uci_parse_package in file.c and uci_strdup in util.c.
CRITICAL · CVSS 9.8
EPSS 0.00507
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0