NULL pointer dereference in ZenLib - CVE-2020-36646
Published: May 1, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error within the Ztring::Date_From_Seconds_1970_Local() function of the file Source/ZenLib/Ztring.cpp. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.
Affected software
Ubuntu
libzen-dev (Ubuntu package)
libzen0v5 (Ubuntu package)
libzen0 (Ubuntu package)
How to mitigate CVE-2020-36646
libzen-dev (Ubuntu package) - addressed in versions Ubuntu Pro, 0.4.37-1ubuntu0.18.04.1, 0.4.37-1ubuntu0.20.04.1
libzen0v5 (Ubuntu package) - addressed in versions Ubuntu Pro, 0.4.37-1ubuntu0.18.04.1, 0.4.37-1ubuntu0.20.04.1
libzen0 (Ubuntu package) - update to Ubuntu Pro