CVE-2021-20204 is a critical heap memory corruption vulnerability (use-after-free) in libgetdata v0.10.0, affecting Debian and Fedora distributions. This flaw can be triggered by processing maliciously crafted dirfile databases, impacting the confidentiality, integrity, and availability of software utilizing the library. With a CVSS score of 9.8, it presents a severe risk of arbitrary code execution or privilege escalation, requiring no user interaction or complex attack vectors. While no active exploits, Metasploit modules, or ExploitDB entries are currently available, and community discussion is minimal, the high FAUCET Risk Score of 82/100 indicates its significant potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.10.0CPE matchmatch criteria | cpe:2.3:a:getdata_project:getdata:0.10.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.