CVE-2019-20503

Source
https://cve.org/CVERecord?id=CVE-2019-20503
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-20503.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-20503
Downstream
AZL (2)
DEBIAN (1)
MGASA (3)
openSUSE (9)
RHSA (9)
SUSE (4)
UBUNTU (1)
Related
Published
2020-03-06T20:15:12Z
Modified
2026-07-08T20:42:28Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.

Database specific
{
    "unresolved_ranges":  [
        {
            "cpes":  [
                "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*",
                "cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:esm:*:*:*",
                "cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "introduced":  "16.04"
                },
                {
                    "last_affected":  "16.04"
                },
                {
                    "introduced":  "18.04"
                },
                {
                    "last_affected":  "18.04"
                },
                {
                    "introduced":  "19.10"
                },
                {
                    "last_affected":  "19.10"
                }
            ],
            "source":  "CPE_STRING",
            "vendor_product":  "canonical:ubuntu_linux"
        },
        {
            "cpes":  [
                "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
                "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*",
                "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "introduced":  "8.0"
                },
                {
                    "last_affected":  "8.0"
                },
                {
                    "introduced":  "9.0"
                },
                {
                    "last_affected":  "9.0"
                },
                {
                    "introduced":  "10.0"
                },
                {
                    "last_affected":  "10.0"
                }
            ],
            "source":  "CPE_STRING",
            "vendor_product":  "debian:debian_linux"
        }
    ]
}
References

Affected packages

Git / github.com/sctplab/usrsctp

Affected ranges

Type
GIT
Repo
https://github.com/sctplab/usrsctp
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:usrsctp_project:usrsctp:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "0.9.4.0"
        }
    ],
    "source":  [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.9.3.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-20503.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "327730508206728550863753806873793731736",
                "232271758629531299930137668846449714744",
                "194005753297318196458770335547941487347",
                "86204924904057636553596664040784693774",
                "244136754859619190609903659491420283679",
                "44612721252499536122830739299996825008",
                "116186934364462999016852279057551526709",
                "64501329213993218393816168186692126019",
                "119328532300576277392225218027534876256",
                "329598022706840916657844249803604086365",
                "176396067618788986641177387171929621588"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2019-20503-14ff5ff7",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/sctplab/usrsctp/commit/790a7a2555aefb392a5a69923f1e9d17b4968467",
        "target":  {
            "file":  "usrsctplib/netinet/sctp_pcb.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "27420102985421191217555899899753575960",
            "length":  3188
        },
        "id":  "CVE-2019-20503-185f67a0",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/sctplab/usrsctp/commit/790a7a2555aefb392a5a69923f1e9d17b4968467",
        "target":  {
            "file":  "usrsctplib/netinet/sctp_auth.c",
            "function":  "sctp_auth_get_cookie_params"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "198649497057395982509242331217339772045",
                "326714267827621994314007627938541425994",
                "200687103341371863484723060369228893508",
                "35232636956357906578787539674949587156",
                "293811026459325849753854165102556642130",
                "187752912983013076529152616624826225304",
                "177037905624134339009325707825459025466"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2019-20503-e574742e",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/sctplab/usrsctp/commit/790a7a2555aefb392a5a69923f1e9d17b4968467",
        "target":  {
            "file":  "usrsctplib/netinet/sctp_auth.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "72565663288024329373879027215936898435",
            "length":  12999
        },
        "id":  "CVE-2019-20503-e903d135",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/sctplab/usrsctp/commit/790a7a2555aefb392a5a69923f1e9d17b4968467",
        "target":  {
            "file":  "usrsctplib/netinet/sctp_pcb.c",
            "function":  "sctp_load_addresses_from_init"
        }
    }
]
vanir_signatures_modified
"2026-07-08T20:42:28Z"