CVE-2020-18897 describes a use-after-free vulnerability in the libpff_item_tree_create_node function of libyal Libpff versions prior to 20180623, affecting the libpff_project. This flaw allows attackers to trigger a denial of service or execute arbitrary code by crafting a malicious pff file. Rated 7.8 HIGH, exploitation requires local access and user interaction (e.g., opening a crafted file), but can lead to high confidentiality, integrity, and availability impacts. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20180623CPE matchmatch criteria | cpe:2.3:a:libpff_project:libpff:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.