VYPR
Low severity3.3NVD Advisory· Published Aug 19, 2021· Updated Jun 17, 2026

CVE-2020-18900

CVE-2020-18900

Description

A heap-based buffer overflow in the libexe_io_handle_read_coff_optional_header function of libyal libexe before 20181128. NOTE: the vendor has disputed this as described in libyal/libexe issue 1 on GitHub

Affected products

3
  • cpe:2.3:a:libexe_project:libexe:*:*:*:*:*:*:*:*
    Range: <20181128
  • Libyal/libexecpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <20181128

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.