← Back to browse · API

CVE-2021-20204

Severity
CRITICAL
CVSS
9.8
EPSS
0.02157
Risk score
39.95
CISA KEV
No
PoC
No
Published
2021-05-06
Modified
2024-10-17
First seen
2026-08-07
Aliases
EUVD-2021-7648, GHSA-MJC7-82X6-3544
Products
n/a:getdata v0.10.0
Sources
euvd EUVD-2021-7648

Description

A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This degrades the confidentiality, integrity and availability of third-party software that uses libgetdata as a library. This vulnerability may lead to arbitrary code execution or privilege escalation depending on input/skills of attacker.

References